Image result for cissp

1.2.2 Organizational Processes

Security governance needs to address every aspect of an organization. This includes the organizational processes of acquisitions, divestitures, and governance committees. 

Acquisitions and mergers place an organization at an increased level of risk, which includes inappropriate information disclosure, data loss, downtime, or failure to achieve sufficient return on investment(RIO).

Divestiture or any form of asset or employees reduction is another time period of increased risk and thus increased the need for focused security governance. 

  • Assets need to be sanitized to prevent data leakage. 
  • Employees released from duty need to be debriefed. This is also known as exit interview. This process usually involves reviewing any nondisclosure agreements as well as any other binding contracts or agreement that will continue after employment has ceased.  

Change Management

Change can introduce loopholes, overlaps, missing objects and oversights that can lead to new vulnerabilities.

The security in change management involves extensive planning, testing, logging, auditing, and monitoring or activities related to security controls and mechanisms. 

The goal of change management is to ensure that any change does not lead to reduced or compromised security. 

It is also responsible for making it possible to roll back any change to a previously secured state. 

Its primary purpose is to make all changes subject to detailed documentation and auditing and thus able to be reviewed and scrutinized by management. 

It should oversee alterations to every aspect of a system, including hardware configuration and operating system and application software. 

It should be included in design, development, testing, evaluation implementation, distribution, evaluation growth, ongoing operation and modification.  

It requires a detailed inventory of every component and configuration.

Users are informed of changes before they occur to prevent loss of productivity. 

The effect of changes are systematically analyzed to determine whether security or business processes are negatively affected. 

The changes are reviewed and approved by a Change Advisory Board (CAB).

 

Data Classification

Data classification, or categorization, is the primary means by which data is protected based on its need for secrecy, sensitivity, or confidentiality. 

It is inefficient to treat all data the same way when designing and implementing a security system because data items need more security than the others.  

Securing everything at a high-security level is too expensive and restricts access to unclassified, noncritical data. 

Data classification is used to determine how much effort, money and resources are allocated to protect the data and control access to it. 

 Data classification or categorization is the process of organizing items, objects, subjects, and so on into groups, categories or collections with similarities. These similarities included value, cost, sensitivity, risk, vulnerability, power, privilege, possible levels of loss or damage, or need to know.

The primary objective of data classification is to formalize and stratify the process of securing data based on assigned labels of importance and sensitivity. 

Data classification is used to provide security mechanisms for storing, processing and transferring data. It also addresses how data is removed from a system and destroyed. 

The following benefits of using data classification scheme:

 It demonstrates an organizations commitment to protecting valuable resources and assets.

It assists in identifying those assets that are most critical or valuable to the organization.

It lends credence to the selection of protection mechanisms,

It is often required for regulatory compliance or legal restrictions. 

It helps to define access levels, types of authorized uses and parameters for declassification and/or destruction of resources that are no longer valuable. 

It helps with data lifecycle management which in part is the storage length, usage and destruction of the data. 

Following seven major steps/phases are used in the classification scheme. 

1. Identify the custodian, and define their responsibilities.

2. Specify the evaluation criteria or how the information will be classified and labelled. 

3. Classify and label each resource.

4. Document any exceptions to the classification policy that are discovered, and integrate them into the evaluation criteria. 

5. Select the security controls that will be applied to each classification level to provide the necessary level of ore protection.

6. Specify the procedures for declassifying resources and the procedures for transferring custody of a resource to an external entity.  

7. Create an enterprise-wide awareness program to instruct all personal about the classification system. 

Declassification is often overlooked when designing a classification system and documenting usage procedures. 

Declassification is required once an asset no longer warrants or needs the protection of its currently assigned classification or sensitivity level. 

There are five levels of government/military classification:

Top Secret: It has the highest level of classification. The unauthorized disclosure of top-secret data will have drastic effects and cause grave damage to national security. The data is compartmentalized on a need-to-know basis such that a user could have top-secret clearance and have access to no data until the user has a need to know.

Secret: It is used for data of a restricted nature. The unauthorized disclosure of data classified as secret will have significant effects and cause critical damage to national security.

Confidential: It is used for data of a sensitive, proprietary, or highly valuable nature. The unauthorized disclosure of data classified as confidential will have noticeable effects and cause serious damage to national security.

Sensitive but unclassified :(SBU) is used for data that is for internal use or for office use only. Often is used to protect information that could violate the privacy rights of individuals.

Unclassified: It is used for data that is neither sensitive nor classified. The disclosure of unclassified data does not compromise the confidentiality of cause any noticeable damage.

 

The CISSP exam focuses on four common or possible business classification levels

Confidential: It is the highest level of classification. It is used for data that is extremely sensitive and for internal use only. Sometimes the label proprietary is substituted for confidential. The proprietary data is considered a specific form of confidential information. If it is disclosed, it can have drastic effects on the competitive edge of an organization.

Private: It is used for data that is of a private or personal nature and intended for internal use only. If it is disclosed a negative impact could occur on the company or individuals. 

The difference between Confidential and Private data is that confidential data is company data whereas private data is data related to individuals.

Sensitive: It is used for data that is more classified than public data. A negative impact could occur for the company if sensitive data is disclosed.

Public: It is the lowest level of classification, it is used for all data that does not fit one of the higher classifications, Its disclosure does not have a serious negative impact on the organization. 

 

Another consideration related to data classification or categorization is ownership. Ownership is the formal assignment of responsibility to an individual or group. The Owner has full capabilities and privileges over the object they own. 

A company document can define owners for the facility, business tasks, process, assets and so on. The ownership of a physical object, intangible asset, or organization concept is defined only on paper and can be more easily undermined. 

Additional security governance must be implemented to provide enforcement of ownership in the physical world.