Topic 7: Blueprint For Security (Part 2)
okay so this are the policy standards
and practices as I mentioned earlier
policy will drive the standards and
standards will drive the practices
procedures and guidelines security
program policy also known as general
security policy or IT security policy or
provisions 15 policy this policy sets
the strategic directions core and tone
for all security efforts within the
organization the SS the SPP or scooty
program policy is an executive-level
document usually drafted by or with the
CIO of the position initially and is
usually eaten are usually two to ten
pages long when the SSP has been
developed this year the C is co the
chief information security officer
begins forming disability in and
initiates their security software
development life cycle process so as you
can see on the screen now is the
enterprise information security policy
so this is one example of Politico
current policy so this e is P we set
strategic directions scope and tone for
all security efforts within the
organization
it is a scooty pliable document usually
drafted by or will say Oh and typically
addresses compliance in two areas first
one is ensure meeting appointments
establish program have responsibilities
assign their into various authorization
organizational components and then
second is the use of specific penalties
and disciplinary chin the second type of
policy is the issue of specific security
policy as the organization is accused
various technologies and processes to
support negative operations certain
guidelines are needed to
employees to use these technologies and
processes properly in general the ISSP
addresses specific areas of technology
requires frequent updates and contains
and issue statements on the
organization's position on an issue
therefore there are numbers of
approaches towards creating and managing
i SS piece within an organization so the
three of the three of the most common
are create a number of independent ISSP
documents each tailored to a specific
issues create a single comprehensive
ISSP document attempting to cover all
shows and the last one is create a
modular RSS feed of burn that unifies
police operations and administration
while maintaining issues specific issues
requirement another one is another type
of policy is system specific policy
while issue specific policies are
formalized as written documents
distribute to users and agreed to in
writing system specific policy are
frequently codified as standards and
procedures used when configuring or
maintaining systems system specific
policy is fall into two groups the first
one is access control list which is
consists of the access control lists
increases and capability levels
governing the rights and privilege of a
particular user to a particle systems
and the second group is configuration
rules which comprise the specific
configuration codes entered into system
entered into security system to guide
the education of their system
previously both Microsoft Windows NT in
2000 and noble net rare - s families of
sister translate is CL into sets of
configuration demonstrators used to
control access to this perspective
system so these are one example of
system specific policies that you can
refer to
okay now we move to policy management
policy are living documents that must be
managed in nature and are constantly
changing and growing this document be
properly this method and manage special
considerations should remit for
organizations and the towing measures
take offers and partnerships in order to
remain viable these policies must have
an individual responsible for reviews
scheduled for the top reviews our method
for making recommendations for reviews
and an indication of policies and
revision did we also have automated
policy management okay so there is an
emergence of new category of software
for managing information security
policies in recent years this category
has emerged in response to needs
particulate by information security
practitioners while there have been many
software products that need specific
technical come to needs there is now a
need for software to automate some of
the busy work of policy management
[Music]
okay the classification of information
is an important aspect of policy the
same protection scheme created to
prevent production data from accidental
released to the wrong party should be
applied to policies in order to keep
them freely available but only within
the organization into this open office
environment it may be beneficial to
implement a clean desk policy a clean
desk policy stipulates that at the end
of the business day all can see file
information must be properly stored in
secure the next we move to the
information security blueprint so this
is actually the basis or the framework
for planning ok basis for design
selection and implementation for all
security policies education and training
programs and technical technological
controls more detailed version of
security framework which is outline of
overall informations will search the
cheap organizations in the blue green
vision
specify tasks to be accomplished and the
order in which they are to be realized
the blueprint also should serve as clip
unscalable up readable and comprehensive
plan for intelligence which is need for
their futures the coming years ok now we
move to the standards that we can refer
to ok one of the most widely referenced
and often discuss cotton Modell is the
information technology equal of practice
for information security management
which was originally published as the
british standard BS 7 799 but as time
goes by and evolve this be a seven seven
nine nine has been divided into two part
that is the is oh one seven seven
ninety-nine
also ISO to seven zero zero one okay it
is the framework for information
security test it's about national
security policy is needed to provide
management direction and spot you can
read more about the different both here
in this link G apart from the ISO
standards we also have the NIS T
security models another possible
approach described in documents
available from community resources
center of an ISD so they are if you are
referring to the eye and is d800 a
series there are many these documents
that describe about the security
components another apart from the
standards we also are going to look at
the IETF security architecture so this
architecture is actually a security area
working group act as Elvis V advised we
bought four protocols and areas they
have looked and promoted by the Internet
Society while no specific architecture
is promoted to the internet Engineering
Task Force the security area working
group act as advisory board for the
protocols and area developed and
promoted to the Internet Society okay so
we can you can refer to RFC two one six
which is the site for the handbook
covers 5se area of spooty with detailed
discussion on development and
implementation we also can refer to the
baselining and best business practices
we have discussed this one in topic six
okay so these two are solid methods for
collecting security practices but
provide less detailed and complete
methodology
possible to get information by
baselining and using best practice does
work backwards to an effective design
we also can refer to the federal agency
Scootie processes because it has some
best practices for public agencies and
adapted easily to private institution so
you can refer to this one as well okay
we can have a hybrid formation and
promote for a blueprint of efficient
security system yes there's no wrong way
to combine an investment that we
prepared when you like to prepare a
blueprint
result of the tenses of component of all
document standards and web-based
information described previously so you
combine all of them and make it as a
your blueprint okay
design of security architecture dear
friends in death so in this context you
have to explain that a copter defensin
mention about implementation of security
layers requires the organization
requires the emulation established
sufficient security controls and
safeguards so that an intruder faces
multiple layers of control and for the
security parameter the point at which
analyzation security protections end in
the out sites will begin is referred to
as desk routine parameters okay
unfortunately the parameters does not
apply to internet attacks from employee
tress or on-site physical threats so you
can have the you can design your scooter
picture but from the outside okay
included in your blueprint is the key
technology components okay we can have
firewalls we can have DMZ intrusion
detection system and many I'm the key
technology components in cryptography
access controls and so on okay
so last but not least is having the
security education training and
awareness program as soon as generous to
the policy Azeez policies to implement
security education training and
awareness programs should follow seta is
a control major designed to reduce acid
accessibility pictures with the
education and training builds on the
general knowledge the employee must
possess to do their job familiarizing
them with the way to do their job
secretly it's very important set a
problem for sub 3 elements security
education for the trainee in security
awareness
everyone in organization needs to
between an array of information security
but not every member of the others
Asians need a formal degree or
certification our certificates in
information security security trainings
involve providing members of
organizations with information in
hands-on instruction why awareness is
giving preparing like a campaign giving
the latest awareness and so on okay so
these are topics the details about
informations with a blueprint okay - so
to summarize we should know that in
blueprint looping is the basis for
design selection and implementation of
all security policies education training
program and technological control that
we set for our companies ok so if you
have any questions please ask me during
the live sessions or the whatsapp group
please read more about this topic sama
kumoi rahmatullahi wa barakaatuh so see
you again in another video
Continue with YouTLDR
Analyze another video with Pro
Process a new video, search every timestamp, compare sources, and keep the result in your library.
More transcripts
Explore other videos transcribed with YouTLDR.

Schwarze Löcher Erklärt - Von der Geburt bis zum Tod
Dinge Erklärt – Kurzgesagt · German

Como construir uma esfera de Dyson – A Megaestrutura Suprema
Em Poucas Palavras – Kurzgesagt · Portuguese (Portugal, Brazil)

[Histoire des sciences] L’histoire de l’intelligence artificielle (IA)
CEA · French

ميكانيكا الكم│1│الواقع الوهمى - كيف بدأ الكم ؟!
Sharafestien - شرفشتــاين (Sharafestien) · Arabic

Mi niñez fue un fusil AK-47
Comisión de la Verdad · Spanish

7. Un Remanente Fiel - Pr. Esteban Bohr || Verdades Para Este Tiempo
SUMtv Latino · Spanish

PENGERTIAN RELASI, FUNGSI, DOMAIN,KODOMAIN DAN RANGE
Utak Atik Otak · English

ساعة الأثرياء | الدحيح
New Media Academy Life · Arabic

You Won't Believe How Easy AlpineQuest Software Makes Geological Field Work | Offline Mapping
MOoDY 4 knOwledge · English

Mundos Olvidados
Cinematix · English

🎨 Apa Itu Sebenarnya Pelajaran Seni? #BelajardiRumah
Kok Bisa? · English

Bab-I: Teks Laporan Hasil Observasi kelas 10 SMA/SMK ~ Bahasa Indonesia
Belajar Prestasi · Indonesian