Information Security is more important to modern businesses than ever before. The advent of GDPR and rise in the ubiquitous use of technology has pushed such matters up to the board level in most companies. Despite this, many businesses find managing their InfoSec obligations a difficult, haphazard and confusing process. This can often lead to ineffective policies and procedures that are not adopted universally, or becoming a “tick box” exercise with the need for such controls not being truly understood. This is obviously not desirable and increases the risk of encountering issues. The good news is that it doesn’t have to be this way! In this article I layout the basics of how information security can be robustly managed and utilised in organisations of all shape, size and nature. This provides the basics for creating an effective management solution and highlighting a number of the key considerations. It is not an exhaustive list but should get the grey matter going about what is important within your organisation.

To deliver information security in an organised, effective and joined up manner, you should look to establish an Information Security Management System or ISMS. This can start of very small and simple, growing and adapting to meet the needs as your business continues to grow and evolve. There are a number of ISMS frameworks and approaches available, the most well-known of these being ISO 27001 with its 114 controls and clearly defined requirements for documentation and review along with external audits and certification. Of course, this level of sophistication is not required or even necessary for all businesses.

The important thing is to establish an ISMS that allows you to manage your information security through objectively quantifying the effectiveness of your Information Security measures and provide a method to implement improvements where required.

So what is an ISMS? It is a collection of policies, procedures, records and reviews that govern information security needs in the business.

The basic premise is; If you know what you have, how you use it, where it is and the risks to it, you can design simple and effective policies, procedures and records to manage your information security relevant to your needs. Of course, this isn’t a “one and done” solution, with continuous review and improvement an (if not the) essential element.

The graphic below illustrates how this all fits together:

ISMS Overview

What do I need to Include?

This can vary from business to business, however there are some common areas that are beneficial to consider when planning an ISMS, a brief overview of these can be found below:

Governance of Information security – who is responsible for ensuring policies, procedures and controls are in place, are effective and reviewed to keep them that way. This includes the following:

– Overall responsibility for strategic direction

– Responsibility for identifying legal and regulatory requirements

– Owners of information systems (for granting access etc)

– Owners of hardware assets

– Responsibility for ensuring reviews are completed

Asset Management – By ensuring assets are known and managed we can understand where information is going, the potential risks to it and what controls we need to have in place. There are many ways you can approach this but simply listing assets in accordance with the following groups will provide excellent high level clarity. You can include as much or as little information in each area as you feel is necessary for your purposes:

Hardware assets – Laptops, PCs, Mobile phones, printers, servers and so on. In addition to recording the item, also note who it is assigned to, if it is a shared resource, note this too.

Software assets – All the different software solutions used in the business, locally installed programs, Software as a Service (SaaS) and so on.

Information categories – The types of information within the business and what it is used for

Suppliers – All service providers to your business

People – All employees and contractors within the organisation

Access Control – Controlling both physical and system access is one of the key elements to preserving information security. The following should be considered at a minimum:

– List of all systems and who has access; this could include employees, contractors and third party providers.

– Process for requesting, granting, revoking, altering and recording access to systems and physical areas

– Assignment of system owners to undertake the above steps

– List of keys/fobs/entry cards and who has them – as above, should include all individuals. If keys/fobs/cards only allow access to specific areas this should be recorded

Risk Management – Identification, recording and mitigation of risks to the information security posture of an organisation is absolutely vital to effective InfoSec management. This can strike fear into the hearts of many however it doesn’t need to be complicated. The following aspects should be considered:

– Identification of risks applicable to the business

– A method of prioritising/scoring the risks to the business. Typically, this is done by applying a scoring system to each risk and thus determining a relative level of threat

– Details of controls and measures taken to mitigate and eliminate risks

– Periodic reviews of the risks to ensure complete coverage and accurate information

Change Management – All businesses experience change, whether it be implementing new systems, moving offices, introducing new products or services and so on. This area can cause significant issues as it is very easy to overlook important aspects of current systems and procedures. Therefore a robust Change Management procedure is particularly important, however it is possible to use a single procedure to manage most changes. You could also fold your improvements procedures into this area too. As with all areas of an ISMS this should be tailored and relevant to your business, so even a simple word document listing your key questions and responses can work. You should think about items such as:

– What are we changing?

– Why are we changing it?

– Who does this impact?

– What procedures will be affected?

– What information will be affected?

– Do we need to review our legal/regulatory position?

– What are the possible risks of making the change?

Incident Management – What to do if it all goes wrong! We all hope we will never need to use these procedures and controls but it is an important aspect of any modern business. For a small company, this could be as simple as “Ring the boss” but nonetheless it should be decided ahead of time what should happen. Consideration of the following will help establish an effective Incident Management solution:

– Who is in charge of managing incidents?

– Who notifies affected parties of incidents (customers, colleagues, authorities, etc)?

– What happens if the physical premises are affected (fire, power cut, etc)?

– Which facilities are the most important to get back to BAU?

Training and Awareness – All the information security measures in the world are useless if no-one knows about them, why they exist and what they are designed to do! The people making up your teams are your best asset in ensuring a robust information security posture. Therefore, you must consider how you will impart this information to those that need it. The following questions will help you get started:

– Do all employees have the same basic understanding of information security?

– Do all employees need to receive the same training or could it be department/role specific (junior, management, board, etc)?

– How is training to be delivered (classroom, self-serve, infographics, other methods)?

– How is training to be monitored and recorded to evidence delivery and understanding?

Reviews – It is vital that you regularly review your system to ensure it is relevant and effective. Different aspects can be reviewed with varying frequencies, for example a simple brochure-ware website does not need to be reviewed as often as your core CRM. Some important areas are:

– Documentation (policies, procedures and records)

– Hardware assets in use

– Information systems in use

– Access to physical premise, hardware assets and information systems

– Risks to the business and operations

Documenting and Recording the System

All of the above listed areas (and others relevant to your business) are generally managed through the application of Policies, Procedures and Records. The purpose of these can be summed up at the basic level in the following way:

Policies, Procedures & Records Overview

Policies

There is a common misconception that policies have to be long and complicated but this is not true. Instead, keep your policies lean and only include what is relevant to you. For example, Fax machines still crop up in policy documentation despite most businesses not using them anymore! It is really useful to include the purpose, scope and key principles the policies are endeavouring to cover at the start of each document. Some key policies to consider are:

Information Security Policy – This should cover what you consider to be within the scope of your information security efforts, the intended goals and how they are to be governed.

Privacy Policy – You really should have one of these already, but if not – get on it! A privacy policy should explain in plain language what information you process, why, how long you keep it, any sharing with 3rd parties, your legal basis and how individuals can exercise their rights in respect of the information you are processing.

Access Control Policy – How you will decide who needs access to what information and resources. This should include who has responsibility for managing access, how credentials should be issued/governed (e.g. No sharing!), frequency of review, limitations based on classification, individuals’ responsibilities, minimum requirements and so on. Applies to technology controls as well as physical access to buildings, rooms etc.

Information Classification Policy – In order to ensure you deploy appropriate effort to protecting information it makes sense to determine a classification system. This should be considered in terms of the level of risk differing types of information present should they be lost of stolen. The following infographic provides a great starting point on which you can build:

Information Classification

Of course, there are a number of other policies one should consider in addition such as Acceptable Use, Passwords, Cryptographic controls, Supplier Security and so on, however that goes someway beyond the scope of this piece and would make it a book! There are a number of online resources that can go into more detail in this area. Once again though, the key is to consider what is relevant and appropriate to your business.

Procedures

Procedures documentation should be similarly kept as simple as possible and don’t limit yourself to long bullet point action lists – Consider flowcharts, infographics, videos or a combination – Whatever works best in your organisation and with your teams! The key point is having a central repository of curated procedural information. In addition to documenting operational procedures, it is important to include areas such as incident management, access provisioning, employee onboarding and offboarding. Including these types of areas will ensure that information security requirements can be easily fulfilled. Wherever possible, information security requirements should be folded into the standard operational procedures, not applied as separate, additional steps. E.g. Part of deploying new laptops should include entering them in the hardware records.

Records

Records need to be good enough to show you what you need to know. If you can record it all in a simple spreadsheet and that works for you then that’s perfect! Alternatively, if you want to adopt more technological solutions, both Google’s G-Suite and Microsoft’s Office365 contain tools to help you automatically gather information on hardware and software in use. There are also any number of products on the market to aide in the capturing information in all required areas. Here are the main registers you will need:

Hardware – All the laptops, mobile phones and other devices used in the business

Information Systems – All the software solutions used (including spreadsheets if a critical part of your operation), include information around the level of importance to the business and the types of information contained.

Suppliers – All the service providers to the business, what they do, what information is passed to them and how to contact them.

Risks & Treatments – A list of all risks to the information security of the business and how they are managed/mitigated.

Change Management – What you have changed, why, how and when – This could include implemented improvements as well (these are changes after all!)

Reviews – A list of what reviews have been completed, when, who by and any outcomes. This should include documentation, access rights, risks, assets and so on.

Measures and Metrics

The last aspect to consider, adding objectivity to your reviews through establish some quantifiable measures and the metrics that will support them. As with all other aspects of an ISMS, these should be specific to your business

As mentioned throughout this piece, the specific requirements of individual businesses will vary considerably, the key takeaway is that it doesn’t have to be complicated or long-winded. In fact, the leaner and more specific it is, the more effective it will be. The most important part is making sure it is relevant to what you do. Using the ole’ SMART approach will help you ensure this is achieved. The below infographic provides an example of how this can work:

Smart Objectives

Other measures and metrics worth considering include items such as:

– Number of reviews completed

– Actions arising from completed reviews

– Number of assets recorded vs number in use

– Number of assets with assigned owner vs number in use

– Number of incidents recorded

– Number of risks mitigated vs number of risks identified

– Number of devices (laptops etc) with anti-virus

– Number of admin users vs authorised/appropriate access requirements

It is very useful to include indicators alongside these measures, these can vary dependent on how you go about recording metrics. For example:

– Actions from review: Is a downward or upward trend desired?

– Recorded assets: What is the target percentage in a given time frame?

– Incidents recorded: What total number over what time frame should trigger a review of methodology?

You need to consider how you will gather this information – by and large, this should be available from the records you have created. If it isn’t possible to gather the required information, ask yourself if it is really relevant and if so, how can you implement a policy, procedure or record to capture it.

As you can see, this approach means you can quickly and easily identify where your ISMS is performing well, or where there is a need for further attention. This latter is not necessarily a bad thing as it shows you are meaningfully monitoring activities and actioning improvements where required.

So that’s it for this basic introduction. There are a multitude of tools and resources available to help implement robust information security however they are not always necessary. The most important thing is that you and your teams understand why it is important and where to get guidance and information when needed. An organised ISMS will ensure that is possible whilst providing robust indicators that what you are doing is working.

Similar Posts