Full Transcript

·YouTLDR

Topic 7: Blueprint For Security (Part 2)

14:53EnglishBy Najwa AlwiTranscribed Jul 18, 2026
Analyze another video with Pro30-day money-back guarantee
0:02

okay so this are the policy standards

0:07

and practices as I mentioned earlier

0:10

policy will drive the standards and

0:13

standards will drive the practices

0:15

procedures and guidelines security

0:26

program policy also known as general

0:31

security policy or IT security policy or

0:35

provisions 15 policy this policy sets

0:38

the strategic directions core and tone

0:41

for all security efforts within the

0:43

organization the SS the SPP or scooty

0:48

program policy is an executive-level

0:51

document usually drafted by or with the

0:54

CIO of the position initially and is

0:57

usually eaten are usually two to ten

1:01

pages long when the SSP has been

1:03

developed this year the C is co the

1:06

chief information security officer

1:08

begins forming disability in and

1:10

initiates their security software

1:13

development life cycle process so as you

1:17

can see on the screen now is the

1:19

enterprise information security policy

1:21

so this is one example of Politico

1:24

current policy so this e is P we set

1:27

strategic directions scope and tone for

1:30

all security efforts within the

1:31

organization

1:33

it is a scooty pliable document usually

1:35

drafted by or will say Oh and typically

1:39

addresses compliance in two areas first

1:42

one is ensure meeting appointments

1:44

establish program have responsibilities

1:46

assign their into various authorization

1:50

organizational components and then

1:52

second is the use of specific penalties

1:55

and disciplinary chin the second type of

2:00

policy is the issue of specific security

2:02

policy as the organization is accused

2:07

various technologies and processes to

2:09

support negative operations certain

2:12

guidelines are needed to

2:13

employees to use these technologies and

2:15

processes properly in general the ISSP

2:20

addresses specific areas of technology

2:23

requires frequent updates and contains

2:26

and issue statements on the

2:28

organization's position on an issue

2:32

therefore there are numbers of

2:35

approaches towards creating and managing

2:38

i SS piece within an organization so the

2:42

three of the three of the most common

2:44

are create a number of independent ISSP

2:51

documents each tailored to a specific

2:53

issues create a single comprehensive

2:56

ISSP document attempting to cover all

2:59

shows and the last one is create a

3:02

modular RSS feed of burn that unifies

3:05

police operations and administration

3:07

while maintaining issues specific issues

3:10

requirement another one is another type

3:18

of policy is system specific policy

3:23

while issue specific policies are

3:26

formalized as written documents

3:28

distribute to users and agreed to in

3:30

writing system specific policy are

3:34

frequently codified as standards and

3:37

procedures used when configuring or

3:40

maintaining systems system specific

3:43

policy is fall into two groups the first

3:46

one is access control list which is

3:50

consists of the access control lists

3:52

increases and capability levels

3:54

governing the rights and privilege of a

3:57

particular user to a particle systems

3:59

and the second group is configuration

4:02

rules which comprise the specific

4:05

configuration codes entered into system

4:08

entered into security system to guide

4:11

the education of their system

4:23

previously both Microsoft Windows NT in

4:26

2000 and noble net rare - s families of

4:30

sister translate is CL into sets of

4:33

configuration demonstrators used to

4:35

control access to this perspective

4:37

system so these are one example of

4:41

system specific policies that you can

4:43

refer to

4:54

okay now we move to policy management

4:56

policy are living documents that must be

4:59

managed in nature and are constantly

5:03

changing and growing this document be

5:06

properly this method and manage special

5:09

considerations should remit for

5:11

organizations and the towing measures

5:14

take offers and partnerships in order to

5:17

remain viable these policies must have

5:20

an individual responsible for reviews

5:23

scheduled for the top reviews our method

5:26

for making recommendations for reviews

5:29

and an indication of policies and

5:32

revision did we also have automated

5:38

policy management okay so there is an

5:44

emergence of new category of software

5:45

for managing information security

5:47

policies in recent years this category

5:50

has emerged in response to needs

5:52

particulate by information security

5:54

practitioners while there have been many

5:56

software products that need specific

5:58

technical come to needs there is now a

6:00

need for software to automate some of

6:02

the busy work of policy management

6:08

[Music]

6:14

okay the classification of information

6:20

is an important aspect of policy the

6:24

same protection scheme created to

6:26

prevent production data from accidental

6:28

released to the wrong party should be

6:30

applied to policies in order to keep

6:33

them freely available but only within

6:35

the organization into this open office

6:38

environment it may be beneficial to

6:40

implement a clean desk policy a clean

6:43

desk policy stipulates that at the end

6:45

of the business day all can see file

6:48

information must be properly stored in

6:50

secure the next we move to the

6:58

information security blueprint so this

7:00

is actually the basis or the framework

7:07

for planning ok basis for design

7:11

selection and implementation for all

7:15

security policies education and training

7:19

programs and technical technological

7:21

controls more detailed version of

7:23

security framework which is outline of

7:26

overall informations will search the

7:28

cheap organizations in the blue green

7:31

vision

7:32

specify tasks to be accomplished and the

7:35

order in which they are to be realized

7:38

the blueprint also should serve as clip

7:42

unscalable up readable and comprehensive

7:46

plan for intelligence which is need for

7:48

their futures the coming years ok now we

8:00

move to the standards that we can refer

8:02

to ok one of the most widely referenced

8:04

and often discuss cotton Modell is the

8:07

information technology equal of practice

8:09

for information security management

8:10

which was originally published as the

8:14

british standard BS 7 799 but as time

8:18

goes by and evolve this be a seven seven

8:21

nine nine has been divided into two part

8:25

that is the is oh one seven seven

8:27

ninety-nine

8:28

also ISO to seven zero zero one okay it

8:38

is the framework for information

8:39

security test it's about national

8:41

security policy is needed to provide

8:42

management direction and spot you can

8:45

read more about the different both here

8:47

in this link G apart from the ISO

8:53

standards we also have the NIS T

8:56

security models another possible

8:58

approach described in documents

9:00

available from community resources

9:03

center of an ISD so they are if you are

9:06

referring to the eye and is d800 a

9:09

series there are many these documents

9:13

that describe about the security

9:18

components another apart from the

9:24

standards we also are going to look at

9:27

the IETF security architecture so this

9:31

architecture is actually a security area

9:38

working group act as Elvis V advised we

9:42

bought four protocols and areas they

9:44

have looked and promoted by the Internet

9:46

Society while no specific architecture

9:49

is promoted to the internet Engineering

9:51

Task Force the security area working

9:54

group act as advisory board for the

9:56

protocols and area developed and

9:58

promoted to the Internet Society okay so

10:03

we can you can refer to RFC two one six

10:06

which is the site for the handbook

10:08

covers 5se area of spooty with detailed

10:11

discussion on development and

10:13

implementation we also can refer to the

10:19

baselining and best business practices

10:22

we have discussed this one in topic six

10:25

okay so these two are solid methods for

10:30

collecting security practices but

10:31

provide less detailed and complete

10:33

methodology

10:34

possible to get information by

10:36

baselining and using best practice does

10:38

work backwards to an effective design

10:44

we also can refer to the federal agency

10:47

Scootie processes because it has some

10:51

best practices for public agencies and

10:54

adapted easily to private institution so

10:56

you can refer to this one as well okay

10:58

we can have a hybrid formation and

11:00

promote for a blueprint of efficient

11:02

security system yes there's no wrong way

11:05

to combine an investment that we

11:08

prepared when you like to prepare a

11:10

blueprint

11:11

result of the tenses of component of all

11:14

document standards and web-based

11:16

information described previously so you

11:19

combine all of them and make it as a

11:22

your blueprint okay

11:33

design of security architecture dear

11:35

friends in death so in this context you

11:39

have to explain that a copter defensin

11:43

mention about implementation of security

11:45

layers requires the organization

11:50

requires the emulation established

11:52

sufficient security controls and

11:54

safeguards so that an intruder faces

11:57

multiple layers of control and for the

12:00

security parameter the point at which

12:03

analyzation security protections end in

12:05

the out sites will begin is referred to

12:08

as desk routine parameters okay

12:10

unfortunately the parameters does not

12:12

apply to internet attacks from employee

12:14

tress or on-site physical threats so you

12:18

can have the you can design your scooter

12:21

picture but from the outside okay

12:27

included in your blueprint is the key

12:30

technology components okay we can have

12:33

firewalls we can have DMZ intrusion

12:36

detection system and many I'm the key

12:40

technology components in cryptography

12:43

access controls and so on okay

12:51

so last but not least is having the

12:56

security education training and

12:58

awareness program as soon as generous to

13:02

the policy Azeez policies to implement

13:05

security education training and

13:06

awareness programs should follow seta is

13:11

a control major designed to reduce acid

13:14

accessibility pictures with the

13:16

education and training builds on the

13:18

general knowledge the employee must

13:21

possess to do their job familiarizing

13:23

them with the way to do their job

13:25

secretly it's very important set a

13:28

problem for sub 3 elements security

13:31

education for the trainee in security

13:33

awareness

13:40

everyone in organization needs to

13:43

between an array of information security

13:45

but not every member of the others

13:48

Asians need a formal degree or

13:50

certification our certificates in

13:52

information security security trainings

14:00

involve providing members of

14:02

organizations with information in

14:04

hands-on instruction why awareness is

14:07

giving preparing like a campaign giving

14:09

the latest awareness and so on okay so

14:13

these are topics the details about

14:17

informations with a blueprint okay - so

14:20

to summarize we should know that in

14:23

blueprint looping is the basis for

14:26

design selection and implementation of

14:28

all security policies education training

14:30

program and technological control that

14:33

we set for our companies ok so if you

14:36

have any questions please ask me during

14:40

the live sessions or the whatsapp group

14:42

please read more about this topic sama

14:45

kumoi rahmatullahi wa barakaatuh so see

14:49

you again in another video

Continue with YouTLDR

Analyze another video with Pro

Process a new video, search every timestamp, compare sources, and keep the result in your library.

Get Pro — $12/month30-day money-back guarantee

More transcripts

Explore other videos transcribed with YouTLDR.