Acceptable Use Policies (AUP)

  • What is acceptable use of company assets

Incident Response Roles

  • IR team
  • IT security management
  • Compliance officers
  • Technical staff
  • User community

Software Development Lifecycle (SDLC)

  • Details ways to get from idea to app
  • Change management

Security Standards

  • formal definition for using security technologies and processes

Regulatory Considerations

  • Sarbanes-Oxley Act (SOX)
    • all financial data is protected and accessible to authorized data
  • HIPAA
    • same for medical data

Data roles

  • data controller
    • manages the purpose and means by which personal data is processed
  • data processor
    • processes data on behalf of the data controller, often 3rd party
  • data custodian
    • responsible for data accuracy, privacy, and security

Risk Analysis

Qualitative Risk Assessment

  • Identify risk factors (usually visually)

Quantitative risk assessment

  • value calculated
  • ARO (Annualized Rate of Occurence)
  • Asset value (AV)
  • Exposure Factor (EF)
    • percentage of value lost due to an incident
  • Single Loss Expectancy (SLE)
    • AV * EF
  • Annualized Loss Expectancy (ALE)
    • ARO * SLE

Risk appetite

  • risk-taking deemed acceptable
  • risk appetite posture
    • description for readiness to take risk

risk tolerance

  • an acceptableness variance from the risk appetite

e.g. speed limit of 55 is our risk appetite, risk tolerance the speed at which you will be ticketed

Risk register

  • every project has a plan but also a risk
  • identify risks that could impact org, gives risk owners, and risk thresholds

Business Impact Analysis

Recovery Time Objective (RTO)

  • get back to particular service lelvel

Recovery Point Objective (RPO)

  • how much data loss is acceptable
  • when bringing back systems, how far back does the data go?

Mean Time to repair (MTTR)

  • average time required to fix an issue

Mean time between failures (MTBF)

  • time between outages
  • uptime divided by number of breakdowns

Third-party assessment

Right-to-audit clauses

  • should be in contract
  • have the option to perform a security audit at any time

Have a third-party perform an audit

supply chain analysis

  • system involved when creating a product

Agreement Types

Service Level Agreement (SLA)

  • Minimum terms for services provided
  • uptime, response time agreement, etc.

Memorandum of understanding (MOU)

  • both sides agree in general to the contents of the memorandum
  • states common goals but not more
  • informal letter of intent, not a contract

Memorandum of Agreement (MOA)

  • next step after a MOU
  • both sides conditionally agree to the objectives
  • can be a legal document
    • but not contain legally enforceable promises

Master Service Agreement (MSA)

  • legal contract and agreement of terms
  • framework for later transactions

Work order (WO) or Statement of Work (SOW)

  • specific list of items to be completed
  • used with MSA
  • details scope of the job, location, etc.

Non-disclosure agreeement (NDA)

  • confidentiality agreement between parties
    • information should not be disclosed
  • unilateral or bilateral

Business Partners Agreement (BPA)

  • going into business together
  • financial contract
  • who makes the business decisions?

Compliance

Meeting the standard of laws, policies, and regulations