Management of Information Security, Fourth Edition 11-1
© 2014 Course Technology, Cengage Learning
Chapter 11
Personnel and Security
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Management of Information Security, Fourth Edition 11-2
Lecture Notes
Overview
Chapter 11 introduces the student to the skills and job positions commonly available in
organizations that relate to information security. Next, students learn about the different
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Identify the skills and requirements for information security positions
Teaching Tips
Introduction
1. Explain that maintaining a secure environment requires that the InfoSec department be
Staffing the Security Function
1. Discuss the concept of supply and demand for various skills and experience, and how it
Qualifications and Requirements
1. Explain that many organizations are not certain which certifications InfoSec personnel
should have, and in some cases InfoSec staff lacks established roles and
Management of Information Security, Fourth Edition 11-3
Entering the Information Security Profession
1. Explain that many InfoSec professionals may have prior careers in law enforcement,
military, or careers in other IT areas.
Information Security Positions
1. Stress the importance of standardization of job descriptions within an organization, and
note that InfoSec positions can be classified into one of three areas: those that define,
those that build, and those that administer.
4. Discuss some of the qualifications for a CISO, such as the Certified Information
Systems Security Professional (CISSP) and the Certified Information Security Manager
6. Discuss the six key principles that CISOs should follow in order to advance their
career:
a. Business engagement
f. Relationship management
7. Discuss the role of a security manager, who is accountable for the day-to-day operation
of the InfoSec program.
8. Explain to students that the management of technology requires an understanding of the
technology but not necessarily proficiency in its configuration, operation, or fault
resolution.
9. Provide students with a list of duties that security managers are typically expected to be
Management of Information Security, Fourth Edition 11-4
11. Describe some of the roles of a security technician, such as the configuration of
firewalls, IDPSs, implementation of security software, diagnostics, and coordination
Cisco devices.
13. Note some of the qualifications and position requirements for a security technician.
Students should be aware that organizations typically prefer expert, certified, proficient
technicians.
14. Educate students on the Information Security Engineer job description as noted by
Information Security Professional Credentials
1. Explain how organizations rely on professional certifications in order to gauge
proficiency possessed by an individual in particular topics.
(ISC) 2 Certifications
1. Introduce the International Information Systems Security Certification Consortium
(ISC)2 as an organization that offers security certifications, such as:
2. Discuss the CISSP certification, which is considered to be the most prestigious
certification for security managers and CISOs.
3. Note that the exam requires at least five years of direct, full-time security professional
4. Explain that the CISSP exam consists of 250 multiple choice questions in 10 different
domains of InfoSec:
a. Access control
b. Business continuity and disaster recovery planning
c. Cryptography
5. Educate students on the four additional questions that are asked in addition to the
CISSP exam. Note that an endorsement from an employer or another CISSP holder
Management of Information Security, Fourth Edition 11-5
6. Discuss the concentrations that are available for CISSPs to demonstrate knowledge
beyond the CISSP:
7. Introduce the SSCP certification, and note that it is more suitable for a security
8. Explain that the SSCP certification consists of 125 multiple-choice questions in seven
different domains:
a. Access controls
9. Compare the SSCP to the CISSP, and note that the SSCP also has a requirement for
continued education.
10. The CSSLP should be discussed as a new certification that focuses on the development
11. List the seven experience assessment topics of the CSSLP:
a. Secure software concepts
12. Explain to students that exam takers must be an expert in at least 4 of the seven
experience assessment topics, and must submit one essay for each of the 4 areas.
13. Discuss the Associate of (ISC)2 certification program as being geared for individuals
who may not have the experience to take the CISSP or SSCP exams.
ISACA Certifications
1. Explain the four certifications offered by the Information Systems Audit and Control
Association (ISACA):
Management of Information Security, Fourth Edition 11-6
2. Describe the CISM certification as being intended for InfoSec managers and those who
might have InfoSec management responsibilities. Discuss the different domains of
3. Discuss the certification requirements for applications:
a. Must pass the exam
4. Introduce the Certified Information Systems Auditor (CISA) certification, which is
intended for auditing, networking, and security professionals. List the requirements for
applicants:
a. Successful completion of the exam
b. Experience as an InfoSec auditor, minimum five years professional experience
5. List the five areas of information systems auditing covered by the CISA exam:
a. The Process of Auditing Information Systems (14 percent)
6. Discuss the Certified in the Governance of IT (CGEIT) certification as an exam
targeted at upper level executives that covers areas of knowledge such as risk
7. Note that the requirements for the CGEIT are similar to the other ISACA certifications,
and note that a one year of experience in IT governance and additional experience in at
least two of the domains listed are required.
8. Explain the CRISC certification as being intended for IT professionals as well as
managers, and note the different areas covered by the exam:
Management of Information Security, Fourth Edition 11-7
9. Point out the need for 3 years of experience in risk management and information
systems control across at least three of the stated domains prior to being properly
certified.
SANS Certifications
1. Discuss the Global Information Assurance Certification (GIAC) available through the
System Administration, Networking, and Security Institute (SANS).
2. Explain the GIAC Information Security Professional (GISP) and GIAC Security
EC-Council Certifications
1. Describe the Certified CISO (C|CISO) certification, which is intended to test security
domain knowledge and executive business management knowledge. List the exam’s 5
different domains and their subcomponents:
a. Domain 1: Governance (Policy, Legal, and Compliance)
b. Domain 2: IS Management Controls and Auditing Management (Projects,
CompTIA Certifications
1. The Computing Technology Industry Association (CompTIA) Security + certification
should be introduced as a certification that tests the security knowledge of an individual
with at least 2 years networking experience.
While not a complete guide to the Security+ certification, a free wikibooks topic
Management of Information Security, Fourth Edition 11-8
ISFCE Certifications
1. Explain that the International Society of Forensic Computer Examiners (ISFCE) offer
2. Discuss the requirements for completing the CCE exam:
a. Must have no criminal record
3. List some of the different processes covered by the CCE exam, such as ethics in
practice, software licensing and validation, and use of forensic boot disks.
4. Note that the MCCE certification is obtained by earning three or more endorsements
specializing in different operating systems.
Quick Quiz 1
1. A(n) ____________________ is typically responsible for the configuration of firewalls
and Intrusion Detection and Prevention Systems (IDPSs).
2. True or False: The Chief Information Security Officer needs only to be familiar with
application of InfoSec policy.
3. What is the minimum amount of experience in InfoSec allowed for an applicant to earn
the CISM credential?
A. 2 years
Teaching
Many security-related certifications exist beyond those covered in this book. For
Management of Information Security, Fourth Edition 11-9
B. 3 years
C. 5 years
D. 6 years
4. Which of the following is NOT a CISSP concentration?
A. ISAMP
B. ISSAP
C. ISSMP
D. ISSEP
5. Which job role is accountable for the day-to-day operation of all or part of the InfoSec
program?
A. CISO
B. CSO
C. CEO
Answer: D
Certification Costs
1. Explain to students that certification exams can cost as much as $750, and some
certifications that require more than one exam can easily cost more than a thousand
Employment Policies and Practices
Hiring
1. Make students aware of the necessity to have a dialogue between the CISO, CIO, and
relevant security managers and the human resources personnel so that InfoSec concerns
are addressed in the hiring process.
2. Discuss the importance of having InfoSec responsibilities listed within a job
description, and explain that privileged information should be left out.
Management of Information Security, Fourth Edition 1110
a. Identity checks
b. Education and credential checks
c. Previous employment verification
6. Emphasize that organizations must comply with federal regulations regarding the use of
personal information in employment practices. Note the Fair Credit Reporting Act
(FCRA) as an example of a regulation that organizations must comply with.
Contracts and Employment
1. Discuss the importance of the employment contract, and educate students on what
Security as Part of Performance Evaluation
1. Describe how organizations should incorporate InfoSec components into employee
performance evaluations.
Termination Issues
1. Educate students on the tasks that should be performed whenever an employee leaves
an organization, such as the disabling of user access and changing of locks.
2. Discuss how an exit interview can be conducted to ensure that an employee is aware of
contractual obligations, and can provide feedback.
3. Point out that the termination of an employee exposes an organization to risk, and note
Personnel Security Practices
Management of Information Security, Fourth Edition 1111
1. Describe how organizations can use different methods for monitoring and controlling
employees to minimize misuse of information, such as by using separation of duties.
2. Define collusion as crime or theft that involves more than one person conspiring to
commit a theft or other prohibited action.
3. Explain a two-person control as a control that requires two individuals to review each
other’s work before a task is considered complete.
Security of Personnel and Personal Data
1. Discuss the requirements placed on organizations to protect sensitive employee
Security Considerations for Nonemployees
1. Stress the importance of restricting access to sensitive information by non-employees,
and list some examples of non-employees.
2. Temporary workers, or temps, should be explained as workers that fill temporarily
available positions. Note that a temp working may not be subject to contractual
cooperate.
5. Describe contract workers, or contractors, as employees that are hired to perform
specific functions within an organization.
6. Explain that the needs of a contract employee may require that they have access to
virtually all areas of an organization, but note that some types of contracted workers,
Management of Information Security, Fourth Edition 1112
9. Explain that it might be necessary to utilize nondisclosure agreements in order to
prevent a consultant from discussing work related to an organization with other
potential employers.
the companies, in what format, and with whom.
Quick Quiz 2
1. A(n) ____________________ is often a self-employed or agent contractor, hired to
perform a specific task or work on a specific project.
2. True or False: The CISSP certification is intended for security professionals that may
not have much experience in InfoSec.
3. The __________ is a certification offered by the ISFCE that indicates proficiency with
computer forensics tasks.
4. What is the term used to describe a control that requires that every employee be able to
perform the work of at least one other employee?
A. Task rotation
B. Two-person control
C. Collusion
D. Job rotation
5. Which of the following answers is NOT a common type of background check?
A. Identity checks
B. High school grade check
C. Reference check
D. Credit history
Teaching
Tip
Both movies and TV shows often depict hackers or spies making use of service
uniforms to gain access to secured areas. It is extremely important that an
Management of Information Security, Fourth Edition 1113
Class Discussion Topics
1. Get students to discuss the importance of certification, and have students explain how a
certification helps to verify the skills of an individual.
2. Start a class discussion on the use of code of ethics with certifications as a requirement.
Additional Projects
1. Task students with researching what formal education offerings are available locally for
2. Provide students with a sample non-disclosure agreement, and explain the different
Additional Resources
1. Tech Republic article on the top 10 certifications in IT: