City University of Hong Kong · FACULTY OF INFORMATION TECHNOLOGY

IS6523 Chap.10 Security Planning, Continuity and Implementation

- one subject, every graph, every model, every mark
11 Chapters6-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 10 of 10 · IS6523

Security Planning, Continuity and Implementation

Documents first, and a specific order of them

A security programme begins with the creation or review of policies, standards and practices, then the selection or creation of an architecture and the development of a detailed blueprint that turns intentions into a plan. Without policy, blueprints and planning an organisation cannot meet the security needs of its various communities of interest.

The three document types are distinct: a policy is the course of action conveying instructions from management, standards set out what compliance with it requires, and practices, procedures and guidelines explain how to comply.

The cheapest control and the hardest to land

Security policies are described as the least expensive controls to execute and the most difficult to implement properly, and the conditions attached to effectiveness explain the second half: a policy must be properly disseminated, read, understood, agreed to by all members of the organisation, and uniformly enforced.

Four of those five are facts about people. Policy management carries its own requirements, a named administrator, a review schedule, a method for recommending revisions, an issuance and revision date, and automation where available.

Governance sits above all of it with five named outcomes, and the standards series that delivers them runs as a continuous plan, do, check and act cycle rather than as a project.

Classify the event before it happens, then change the organisation

Three plans answer three situations: incident response for the immediate reaction, disaster recovery to reestablish operations at the primary site, and business continuity, running concurrently when damage is major or long term.

Which plan opens depends on a classification the contingency planning team makes in advance, which is what keeps the decision reviewable. Site options run from hot through warm to cold with cost as the determining factor, alongside shared arrangements and three off-site data mechanisms.

Implementation then changes procedures, people, hardware, software and data, prioritised from general to specific across four layers, with change management treated as a control because the stress of change increases mistakes and creates vulnerabilities.

In this chapter

What this chapter covers

  • 01

    Policy, standard and practice as three different documents

  • 02

    The five conditions a policy must meet to be effective

  • 03

    Policy management and the revision record

  • 04

    Five governance outcomes and three reference models

  • 05

    The improvement cycle and the statement of applicability

  • 06

    A voluntary maturity rating as a supply chain control

  • 07

    Education and awareness as a named control

  • 08

    Incident, disaster and continuity, and who classifies the event

  • 09

    Hot, warm and cold sites, and three off-site data mechanisms

  • 10

    Four conversion strategies and the four layer priority order

  • 11

    Change management, and the three levers of correction

Worked example · free

Open the right plan at two in the morning

Q [7 marks]. AskSia-authored practice. At two in the morning a payment gateway is rejecting every transaction. A storage array has failed and the standby did not take over. Orders cannot be taken. The on-call engineer asks which plan to open. Decide, and say what makes the decision reviewable rather than improvised. The marks shown are an AskSia study allocation, not a University marking scheme.
  • 3Test the event against the definition of an incident.
  • 2Name the plan and its objective.
  • 2Say what makes the choice reviewable.
It is not an incident. An attack is classified as one when it is directed against information assets, has a realistic chance of success and could threaten confidentiality, integrity or availability, and nothing here is directed by anybody. A hardware failure that stops trading is a disaster if the contingency planning team has classified it as one, so the plan to open is the disaster recovery plan, whose objective is to reestablish operations at the primary site; if restoration will take longer than the business can survive, the continuity plan runs concurrently. What makes the choice reviewable is that the course places the decision on which events constitute disasters and which constitute incidents with the planning team in advance, so nobody has to make it at two in the morning.
Sia tip — Check who classified the event before naming the plan. If the classification was made during the incident rather than in advance by the planning team, say so, because that is the defect the question is testing for and it outranks the choice of plan.
Glossary

Key terms

Standard
A more detailed statement setting out what compliance with a policy requires. It is where a policy acquires anything measurable.
Information Security Blueprint
The basis for designing, selecting and implementing policies, education and technical controls, specifying the tasks to be accomplished and the order of them.
Statement of Applicability
The planning output recording which control objectives and controls were selected, and therefore the evidence that an omission was a decision.
Business Impact Analysis
An assessment of the impact various attacks can have, assuming the controls were got round, or failed, or turned out to be ineffective, and that the attack succeeded.
Hot Site
A fully operational alternate facility. It is the shortest route back to service and the most expensive of the dedicated options.
Mutual Agreement
A contract between organisations specifying how each will assist the other in a disaster. It assumes the other party is unaffected by the same event.
Database Shadowing
An off-site arrangement maintaining a full copy of the database at an alternate processing facility, as against vaulting a quantity of data or journaling transaction logs.
Parallel Operation
A conversion strategy running the old and new arrangements together. It carries the least exposure at the moment of change and the highest running cost.
Resilience
The state in which an organisation now treats change as a necessary part of its own culture, so that embracing change is more productive than resisting it.
FAQ

Security Planning, Continuity and Implementation FAQ

Why is a written policy called the cheapest control when it is so often ineffective?

Because the two statements are about different things. Producing the document costs very little compared with any technical control, which is what makes it cheap. What is expensive and difficult is the five conditions attached to effectiveness: dissemination, reading, understanding, agreement and uniform enforcement.

Four of those are facts about people rather than about the text, which is also why ignorance of a policy is an acceptable defence.

How does an organisation know whether it is in an incident or a disaster?

By a classification made before the event. The contingency planning team decides which situations constitute disasters and which constitute incidents, and an attack qualifies as an incident when it is directed at information assets, has a realistic chance of success and could threaten one of the three characteristics.

Deciding it during the event produces an unreviewable judgement taken under pressure by whoever happens to be on call.

What is the weakness of a reciprocal recovery arrangement with a nearby partner?

That it assumes the partner is unaffected. The arrangement is a contract specifying how each party assists the other in a disaster, and a partner in the same area faces the same flood, storm or power failure, so it fails in precisely the scenario it was bought for.

A dedicated site outside the affected area, or a bureau contracted to provide the capability, removes the correlation, with cost deciding which of the three readiness levels is chosen.

Where should work start after a breach traced to a misconfigured application?

Not at the application. The prioritisation method addresses issues from general to specific through policies, networks, systems and then applications, on the stated ground that the focus should be systematic solutions rather than individual problems.

Starting at the application fixes the instance and leaves whatever allowed that configuration to reach production unexamined, which is a policy and change control question rather than a technical one.

Study strategy

Exam move

Write the three plans on one line with the situation each answers beneath, then add the sentence about who classifies the event and when, because that is the part of the chapter that turns into a diagnostic question. Take the six site and sharing options and rank them twice, once by cost and once by time to resume, which is the trade the course says decides between them.

Finally recite the four layer order and apply it to any real incident you know.

Working through Security Planning, Continuity and Implementation in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Security Planning, Continuity and Implementation question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 6 of your City University of Hong Kong subjects - and 1,000+ Bibles across every Australian university.
Sia - your IS6523 tutor, unlimited, worked the way the exam marks it
The full 6-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works