Information Security Program Checklists
Checklist 1: Mission and Priorities
ü Mission
Ø To safeguard the company’s computer systems from all types of security threats and to minimize damage in case of an attack.
ü Priorities
Ø Computing and communication services
Checklist 2: Asset Management
ü The IT management team is responsible for inventoried assets.
Ø Their decisions must be guided by the company’s hardware and software use policy.
ü Inventory information to be classified by the level of security protection required for different hardware and software assets.
ü Storage, documentation, distribution, use, and disposal of IT assets to be guided by relevant compliance laws
ü All stages of information system asset management involve security risk assessments (European Union Agency for Network and Information Security, 2016)
Checklist 3: Organizational Policy Framework
ü Information privacy policy
Ø The company’s data privacy policy provides for the safeguarding of the privacy of PII at all levels of information management, including collection, processing, storage, and use.
Cybersecurity strategy
Ø To develop and maintain an information system that is resilient and hard to compromise.
ü Mobile devices and teleworking policy
Ø All employees must ensure that the use of mobile devices and teleworking communications are secured as provided by the company’s network security policy
ü Communication policy
Ø All employees must adhere to the company’s online communication policy and principles of secure online communications
ü Business Continuity and Recovery
Ø Offsite data backups replicating the company’s critical data to be validated and tested regularly (National Institute of Standards and Technology, 2014)
Checklist 4: Legal and Contractual Requirements
ü The company ought to commit to all legal and contractual requirements about information security
ü Intellectual property, including business records and trade secrets, should be safeguarded
ü The privacy of PII will be a top priority at all levels of data processing and communication.
ü Communications between the company and third parties must be secured using cryptography keys to protect the privacy of PII
ü The company’s information system and employees will be reviewed regularly to ensure compliance with security procedures, standards, and policies (Lockheed Martin, 2015)
Checklist 5: Organization of Information Security
ü The company’s Chief Security Officer and Information Security Managers will be responsible for all matters related to information security
Ø They will be in charge of the company’s Computer Incident Response Teams (CIRT)
ü Information security management to be aligned with ISO/IEC 27000 standards (Forum of Incident Response and Security Teams, 2016)
ü Vendors of information security systems will be responsible for vulnerability and penetration testing.
Ø The Chief Security Officer and Information Security Managers should manage vulnerability and penetration tests to ensure compliance with the company’s information security objectives and priorities.
ü Vendors will be obliged to adhere to contractual agreements related to the security procedures and standards.
Ø Supplier relationship policies will guide decisions about vendors who fail to comply with contractual agreements
ü Contracts with vendors will be audited against the provisions of contractual agreements
Checklist 6: Attack Surface
ü Attack surfaces to be monitored include servers, open ports, Internet access points, online services, web forms, employee platforms, and user interfaces.
ü Types of attacks to watch for
Ø Passive attacks such as port scan, wiretapping, and idle scan.
Ø Active attacks such as DoS attacks, spoofing, network attacks, and host attacks (Northcutt, n.d)
ü The Critical Security Controls V6.0 security framework is to be used to assess the business impact of cyber attacks.
ü Roles of the company’s CIRT
Ø The CIRT will be responsible for handling both passive and active information security breaches
Ø The CIRT must work with the company’s partners in information security, including law enforcement agencies and vendors
Ø The company’s incident response plan will guide the response processes of the CIRT (Forum of Incident Response and Security Teams, 2016).
ü All stakeholders must be informed of security breaches and associated impact on business processes
Checklist 7: Communication Security
ü Firewalls will be used to secure all processes related to information transfer
ü Considerations in perimeter security will include border routers, VPN devices, a software architect, and screened subnets.
ü Intrusion Prevention Systems will be used to detect and mitigate attacks on the company’s databases and network. (Garbars, 2002)
Checklist 8: Access Control
ü Both logical and physical access control mechanisms will be used to safeguard the company’s information systems from intrusion and cyber attacks.
ü Electronic keys and biometric scans will be part of the company’s physical access control measures.
ü Special restrictions such as PINs, passwords, access approval, and authentication, authorization identification will be part of user access management (National Institute of Standards and Technology, 2014)
ü Access rights will be reviewed regularly to ensure that privileged access is effectively controlled.
Checklist 9: Operations Security
ü Protection from malware such as rootkits, viruses, Trojan horses, ransomware, spyware, and adware will be an important aspect of operations security.
ü The company’s Systems-Specific Policy will guide operational procedures, including patching information systems, monitoring of login, and assessing technical vulnerabilities.
Checklist 10: Physical and Environmental Security
ü The company’s physical entry controls include guard force, lockable gates, outside lighting, and intrusion detectors.
ü The IT Disaster Plan must guide all environmental security measures to protect the information system from disasters, such as earthquakes, floods, and fires (Garbars, 2002).
Checklist 11: System Acquisition, Development, and Maintenance
ü Processing of transactions and use of web applications must conform to all security requirements and standards provided by the company’s network security policy.
ü Enterprise data ought to be protected throughout the acquisition, development, and maintenance lifecycle.
ü During change management or system modification, new risks should not be introduced (Lockheed Martin, 2015)
Checklist 12: Human Resource Security
ü Human resource security will focus on preventing internal attacks on the company’s information systems.
ü Pre-employment screening, training, and signing of confidentiality and security agreements are the strategies to be used in ensuring human resource security.
ü Employees who violate their obligations to the provisions of the confidentiality and security agreement will be terminated.
Checklist 13: Evaluation of Information Security Program
ü Periodic reviews of the information security programs will be carried out to determine their effectiveness.
Ø Metrics to be used in the reviews include several security events and technological vulnerabilities, the number of patches deployed, and the number of security events (European Union Agency for Network and Information Security, 2016).
References
European Union Agency for Network and Information Security. (2016). ENISA Threat Landscape 2015.
Forum of Incident Response and Security Teams. (2016). Security Incident Response Team (SIRT) Services Framework.
Garbars, K. (2002). Implementing an effective IT Security Program. SANS Institute 2002.
Lockheed Martin. (2015). Gaining The Advantage of Applying Cyber Kill Chain Methodology to Network Defense.
National Institute of Standards and Technology. (2014, February 12). Framework for Improving Critical Infrastructure Cybersecurity.
Northcutt, S. (n.d.). The Attack Surface Problem.
Ratings
Be Awesome - Share Awesome



