Management of Information Security, Fourth Edition 1-1
Chapter 1
Introduction to the Management of Information Security
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Management of Information Security, Fourth Edition 1-2
Lecture Notes
Overview
This chapter serves as an introduction to information security and project management.
management are covered, as well as useful project management tools.
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Describe the importance of the manager’s role in securing an organization’s use of
information technology and explain who is responsible for protecting an organization’s
Teaching Tips
Introduction
1. Discuss how the need for information security has increased over time, and explain its
necessity within a business environment.
2. Explain that information security funding and planning decisions should involve three
distinct groups:
3. Provide information on the following communities of interest, and elaborate on how
these :
a. Information security community
c. General business community
What Is Security?
1. Elaborate on the meaning of security and how being secure involves the use of risk
assessment and management.
2. Explain the specialized areas of security, and discuss the role of management in
ensuring that security is adequate:
Management of Information Security, Fourth Edition 1-3
a. Physical security
b. Operations security
c. Communications security
d. Network security
3. Introduce the Committee on National Security Systems (CNSS), which was formerly
availability are protected by proper information security.
CNSS Security Model
1. Discuss the CNSS NSTISSI No. 4011 National Training Standard for Information
Systems Security (InfoSec) Professionals document.
2. Explain the McCumber Cube as a model showing the relationship between information
Key Concepts of Information Security
1. Provide students with information on the use of the C.I.A. triangle, which is used to
provide a basic model for information security.
2. Define confidentiality as the restriction of information to only authorized individuals
with proper permissions, and discuss some of the different ways confidentiality is
3. Integrity should be described as the preservation of data in its original, uncorrupted
state. Educate students on some of the risks to data integrity, such as viruses or faulty
Teaching
Tip
In contrast to intrusion detection systems, intrusion prevention systems are more
proactive. Many network and host monitoring systems are actually combinations
of intrusion prevention and intrusion detection systems.
Management of Information Security, Fourth Edition 1-4
5. Identification should be discussed as the way individual users are recognized in a
system. Make students aware of how this is accomplished.
8. Describe accountability as the ability to track each action on a system to a specific user
identity or process running on the system.
What Is Management?
1. Inform students on the proper management of information security, and discuss the
following management roles:
a. Informational role
Behavioral Types of Leaders
1. Compare the three different types of leaders, and familiarize students with the
advantages and disadvantages of each type:
a. Autocratic
Management Characteristics
1. Elaborate on the traditional management theory, which uses the core principles of
planning, organizing, staffing, directing, and controlling (POSDC)
Teaching
More information about the CIA triangle, or triad, can be found below:
Teaching
Many more personality types for leadership exist than are mentioned in this
Management of Information Security, Fourth Edition 1-5
4. Define a goal as the result of a planning process, and explain objectives as a means to
measure progress towards a goal.
5. Explain the organizing process of management as involving the structuring of resources
to support accomplishing objectives.
Solving Problems
1. Provide students with an overview of the 5-step process for solving problems, and give
examples of basic use.
2. Step 1 should be explained as involving the identification of a specific issue or
problem.
information on how managers may attempt to gather and generate ideas.
5. Step 4 should be discussed as the step when solutions are evaluated for their potential in
solving a specific problem. List some of the different feasibility metrics that may be
used to determine potential success of a solution:
Principles of Information Security Management
1. Elaborate on the goals of the information security management team, and discuss how
Planning
1. Describe how a business strategy dictates the development of an IT strategy, which is
then used to develop an information security strategy. Provide students with a general
understanding of how this is typically accomplished in an organization.
Management of Information Security, Fourth Edition 1-6
2. List some of the different types of information security plans and planning functions
that exist:
a. Incident response
b. Business continuity
Policy
1. Discuss the three different general policy categories, and explain how each is used:
a. Enterprise information security policy (EISP)
Programs
1. Explain the existence of information security programs, and specifically mention the
Protection
1. Describe how the protection function is accomplished through risk management
activities.
People
Projects
1. The project function should be explained as involving project management, which
Quick Quiz 1
1. The ____________________ , which is presented in the NSTISSI No. 4011 National
Training Standard for Information Systems (InfoSec) Professionals, shows three
dimensions of characteristics that are essential to Information Security.
Management of Information Security, Fourth Edition 1-7
2. True or False: Data integrity can be affected by virus infections and data
communications errors.
3. What is the name of the process that is used to establish whether or not a user’s identity
is legitimate?
A. Availability
B. Accountability
C. Authorization
D. Authentication
4. Which is not one of the core principles in traditional management theory?
A. Staffing
B. Leading
C. Directing
D. Controlling
5. What is the name for an intermediate point in a planning process, at which progress
towards a goal can be measured?
A. Break point
B. Stop point
C. Objective
D. Directive
Project Management
1. Explain how information security can be considered both a process and a project, due to
the ongoing nature of information security.
2. Elaborate on the difference between operations and projects. Students should
understand that a process is continuous, whereas a project has defined starting and
stopping points.
Management of Information Security, Fourth Edition 1-8
7. Discuss some of the metrics used in determining project success, such as:
a. Project completed early / on time
Applying Project Management to Security
1. Discuss the Project Management Body of Knowledge methodology that is promoted by
PMBoK Knowledge Areas
1. Discuss the different project management knowledge areas, such as integration, scope,
time, cost, and quality.
2. Project integration management should be explained as the coordination of resources,
and list the major elements of project management that require integration:
a. Development of initial project plan
project is expanded or modified.
6. List the different scope management processes:
a. Scope planning
b. Scope definition
c. Scope verification
7. Educate students on the use of project time management, which helps to ensure that
project meets deadlines. Students should be aware that many projects fail due to errors
Management of Information Security, Fourth Edition 1-9
a. Resource planning
b. Cost estimating
c. Cost budgeting
d. Cost control
11. Project quality management should be defined as a way to ensure that project
deliverables meet project specifications. Note that changes made during a project can
14. Make students aware of some of the factors that can affect proper assignment of human
resources to a project, such as different efficiency and skill levels in the work
environment.
15. List the processes that are involved in project human resource management:
a. Organizational planning
b. Staff acquisition
c. Team development
16. Describe the purpose of project communications management in managing the
18. Introduce project risk management as involving the management of risks that could
potentially compromise a project’s success, and note that it is similar to security risk
management.
19. List the different processes that make up project risk management:
a. Risk identification
20. Project procurement management can be explained as the management of gathering
necessary resources for the successful completion of a project.
21. Make students aware of the different processes included in project procurement
management:
a. Procurement planning
Management of Information Security, Fourth Edition 110
Project Management Tools
1. Educate students on some of the different tools and modeling approaches available for
the management of projects.
Work Breakdown Structure
1. Define a work breakdown structure (WBS) as a way to implement a project plan by
separating a project into major tasks.
2. Discuss the attributes that should be identified for each task within a WBS, such as the
Task-Sequencing Approaches
1. Educate students on the network scheduling method for the organization and
sequencing of project tasks.
2. Introduce the Program Evaluation and Review Technique (PERT) as the most popular
and widely used network dependency diagramming technique. Explain how this
technique compares to the Critical Path Method (CPM).
3. Provide students with the three key questions for adding an activity to a PERT diagram:
a. How long will it take?
Automated Project Tools
1. Make students aware of Microsoft Project, which is the most widely used project
management tool.
Management of Information Security, Fourth Edition 111
2. Provide students with guidance on the proper use of project management tools.
Students should understand the advantages and disadvantages of over-reliance on such
Quick Quiz 2
1. The ____________________ , consists of a list of major tasks and attributes, as well as
smaller tasks or specific action steps under each major task.
2. True or False: The Critical Path Method is fundamentally different from the PERT
diagram.
3. A __________ lists activities on a vertical axis, with the horizontal axis representing a
time line.
4. Which of the following represents a sequence of activities or events that take the
majority of time to complete on a CPM diagram?
A. Critical order
B. Absolute path
C. Slack time
D. Critical path
5. Which of the following is not a process covered under project cost management?
A. Quality control
B. Cost control
C. Resource planning
D. Cost estimating
Answer: A
Class Discussion Topics
Management of Information Security, Fourth Edition 112
1. Start a class discussion about which leadership role students believe would be most
2. Give students time to discuss what types of security should be considered when dealing
Additional Projects
1. Provide students with an example project, and have them create a Gantt chart or PERT
diagram that properly models each task within the project.
2. Task students with researching the different types of management approaches. Students
Additional Resources
1. Article containing tips for ensuring project success: