IS6523 Chap.10 Security Planning, Continuity and Implementation
Security Planning, Continuity and Implementation
Documents first, and a specific order of them
A security programme begins with the creation or review of policies, standards and practices, then the selection or creation of an architecture and the development of a detailed blueprint that turns intentions into a plan. Without policy, blueprints and planning an organisation cannot meet the security needs of its various communities of interest.
The three document types are distinct: a policy is the course of action conveying instructions from management, standards set out what compliance with it requires, and practices, procedures and guidelines explain how to comply.
The cheapest control and the hardest to land
Security policies are described as the least expensive controls to execute and the most difficult to implement properly, and the conditions attached to effectiveness explain the second half: a policy must be properly disseminated, read, understood, agreed to by all members of the organisation, and uniformly enforced.
Four of those five are facts about people. Policy management carries its own requirements, a named administrator, a review schedule, a method for recommending revisions, an issuance and revision date, and automation where available.
Governance sits above all of it with five named outcomes, and the standards series that delivers them runs as a continuous plan, do, check and act cycle rather than as a project.
Classify the event before it happens, then change the organisation
Three plans answer three situations: incident response for the immediate reaction, disaster recovery to reestablish operations at the primary site, and business continuity, running concurrently when damage is major or long term.
Which plan opens depends on a classification the contingency planning team makes in advance, which is what keeps the decision reviewable. Site options run from hot through warm to cold with cost as the determining factor, alongside shared arrangements and three off-site data mechanisms.
Implementation then changes procedures, people, hardware, software and data, prioritised from general to specific across four layers, with change management treated as a control because the stress of change increases mistakes and creates vulnerabilities.
What this chapter covers
- 01
Policy, standard and practice as three different documents
- 02
The five conditions a policy must meet to be effective
- 03
Policy management and the revision record
- 04
Five governance outcomes and three reference models
- 05
The improvement cycle and the statement of applicability
- 06
A voluntary maturity rating as a supply chain control
- 07
Education and awareness as a named control
- 08
Incident, disaster and continuity, and who classifies the event
- 09
Hot, warm and cold sites, and three off-site data mechanisms
- 10
Four conversion strategies and the four layer priority order
- 11
Change management, and the three levers of correction
Open the right plan at two in the morning
- 3Test the event against the definition of an incident.
- 2Name the plan and its objective.
- 2Say what makes the choice reviewable.
Key terms
- Standard
- A more detailed statement setting out what compliance with a policy requires. It is where a policy acquires anything measurable.
- Information Security Blueprint
- The basis for designing, selecting and implementing policies, education and technical controls, specifying the tasks to be accomplished and the order of them.
- Statement of Applicability
- The planning output recording which control objectives and controls were selected, and therefore the evidence that an omission was a decision.
- Business Impact Analysis
- An assessment of the impact various attacks can have, assuming the controls were got round, or failed, or turned out to be ineffective, and that the attack succeeded.
- Hot Site
- A fully operational alternate facility. It is the shortest route back to service and the most expensive of the dedicated options.
- Mutual Agreement
- A contract between organisations specifying how each will assist the other in a disaster. It assumes the other party is unaffected by the same event.
- Database Shadowing
- An off-site arrangement maintaining a full copy of the database at an alternate processing facility, as against vaulting a quantity of data or journaling transaction logs.
- Parallel Operation
- A conversion strategy running the old and new arrangements together. It carries the least exposure at the moment of change and the highest running cost.
- Resilience
- The state in which an organisation now treats change as a necessary part of its own culture, so that embracing change is more productive than resisting it.
Security Planning, Continuity and Implementation FAQ
Why is a written policy called the cheapest control when it is so often ineffective?
Because the two statements are about different things. Producing the document costs very little compared with any technical control, which is what makes it cheap. What is expensive and difficult is the five conditions attached to effectiveness: dissemination, reading, understanding, agreement and uniform enforcement.
Four of those are facts about people rather than about the text, which is also why ignorance of a policy is an acceptable defence.
How does an organisation know whether it is in an incident or a disaster?
By a classification made before the event. The contingency planning team decides which situations constitute disasters and which constitute incidents, and an attack qualifies as an incident when it is directed at information assets, has a realistic chance of success and could threaten one of the three characteristics.
Deciding it during the event produces an unreviewable judgement taken under pressure by whoever happens to be on call.
What is the weakness of a reciprocal recovery arrangement with a nearby partner?
That it assumes the partner is unaffected. The arrangement is a contract specifying how each party assists the other in a disaster, and a partner in the same area faces the same flood, storm or power failure, so it fails in precisely the scenario it was bought for.
A dedicated site outside the affected area, or a bureau contracted to provide the capability, removes the correlation, with cost deciding which of the three readiness levels is chosen.
Where should work start after a breach traced to a misconfigured application?
Not at the application. The prioritisation method addresses issues from general to specific through policies, networks, systems and then applications, on the stated ground that the focus should be systematic solutions rather than individual problems.
Starting at the application fixes the instance and leaves whatever allowed that configuration to reach production unexamined, which is a policy and change control question rather than a technical one.
Exam move
Write the three plans on one line with the situation each answers beneath, then add the sentence about who classifies the event and when, because that is the part of the chapter that turns into a diagnostic question. Take the six site and sharing options and rank them twice, once by cost and once by time to resume, which is the trade the course says decides between them.
Finally recite the four layer order and apply it to any real incident you know.
Working through Security Planning, Continuity and Implementation in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Security Planning, Continuity and Implementation question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.