Management of Information Security, Fourth Edition 2-1
Chapter 2
Planning for Security
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Management of Information Security, Fourth Edition 2-2
Lecture Notes
Overview
In chapter 2, students are introduced to the different roles within an organization that are
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Identify the roles in organizations that are active in the planning process
Teaching Tips
Introduction
1. Reiterate the importance of proper planning for information security, and explain the
role of a chief information security officer (CISO) or chief security officer (CSO).
The Role of Planning
1. Explain how planning can involve different groups that can be internal or external to an
organization.
2. Define a stakeholder as a person or organization that has a stake in a specific part of
plan or operation. Explain stockholders as entities that hold stock in a particular
Teaching
Tip
End users themselves can be considered stakeholders in a project, especially if a
project will change how end users perform their day to day tasks. It is absolutely
Management of Information Security, Fourth Edition 2-3
Precursors to Planning
1. Educate students on important elements to be considered prior to planning, such as
specifically stating ethical, entrepreneurial, and philosophical perspectives. Discuss
Values Statement
1. Stress the importance of the values statement, which sets the standard by which an
organization can evaluate itself and its current practices.
Vision Statement
1. Detail the vision statement as a statement containing the aspirations of an organization
Mission Statement
1. Describe how a mission statement is used to indicate the primary business of an
organization and its intended area of operations.
2. Explain that organizations may require the creation of a mission statement for each of
Strategic Planning
1. Explain strategic planning as guiding an organization to the creation of specific goals,
and re-iterate that a good strategic plan utilizes a top-down approach.
Teaching
For more examples of mission statements, see the following page:
Management of Information Security, Fourth Edition 2-4
Creating a Strategic Plan
1. Educate students on how a strategic plan is created by providing an example of how
Planning Levels
1. Explain to students that the next step in strategic planning is to create tasks with
objectives.
2. Note that the strategic plan is used to create tactical plans, and that tactical plans are
used to create operational plans.
3. Tactical plans should be explained as consisting of specific, incremental objectives.
Planning and the CISO
1. Discuss how a strategic plan should be structured, and list some of the basic
components of a typical strategic plan:
a. Executive Summary
b. Mission Statement and Vision Statement
2. Explain how appendices can assist in the identification of new directions or the
elimination of unprofitable directions.
Quick Quiz 1
1. The ____________________ is used to declare the intended areas of operation for a
business.
Management of Information Security, Fourth Edition 2-5
2. True or False: The CISO is another name for a CIO, as both roles perform the same
tasks.
3. Which of the following is not a component of a typical strategic plan?
A. Executive summary
B. Historical profile
C. Organizational profile
D. Strategic issues and core values
4. Which of the following best describes a stakeholder?
A. An individual or group that owns financial stock in an organization
B. A competing organization
C. An individual who buys an organization’s products
D. An individual or group who has a vested interest
5. Which of the following is used to establish a formal set of organizational principles and
qualities for an organization?
A. Values statement
B. Vision statement
C. Mission statement
D. Morals statement
Information Security Governance
1. Define the governance, risk management, and compliance (GRC) approach to
executive-level strategic planning.
2. Make students aware of the fact that information security is a managerial responsibility,
Desired Outcomes
1. Elaborate on the elements that are critical to information security governance, such as
2. Discuss the five basic outcomes of information security governance, and the National
Association of Corporate Directors (NACD) recommendations on essential practices
for boards of directors.
Management of Information Security, Fourth Edition 2-6
Benefits of Information Security Governance
1. Discuss with students some of the benefits of information security governance, such as
Implementing Information Security Governance
1. Educate students on the core set of activities recommended by the Corporate
Governance Task Force (CGTF) for implementation of security governance.
Security Convergence
1. Discuss with students how security-related governance within organizations has merged
over time, and note that accountability for information security has broadened across
different management roles.
2. Explain how enterprise risk management (ERM) can be used to better align security
Planning for Information Security Implementation
1. Teach students about the roles of the CIO and CISO in turning a strategic plan into a
2. Discuss the example of a CISO’s job description from Charles Cresson Wood’s
Information Security Roles and Responsibilities Made Easy.
4. Compare the top-down approach to the bottom-up approach. Note the benefits that are
available when supported by upper-management.
5. Explain the role of a champion, which is ideally an executive, who has the influence to
Management of Information Security, Fourth Edition 2-7
Introduction to the Security Systems Development Life Cycle
1. Define a methodology as an approach to problem solving based on structured sequence
of procedures, and note that a Security Systems Development Life Cycle (SDLC) is a
type of methodology.
5. Educate students on the use of a waterfall model in conjunction with the SecSDLC in
order to illustrate base requirements.
6. Discuss the investigation phase in SecSDLC, and note that it begins as a directive from
upper management within an organization. Students should understand that information
security projects often begin after a significant breach has already occurred.
7. The analysis phase should be explained as the phase where information gathered in the
agent is an individual or group that performs an attack.
10. List some of the different types of technical attacks that can occur:
a. Back door
b. Brute force
c. Buffer overflow
d. Denial-of-service (DoS) and distributed denial-of-service (DDoS)
e. Dictionary
f. DNS cache poisoning
g. Hoax
Management of Information Security, Fourth Edition 2-8
11. Discuss the risk assessment, or risk analysis, step in the analysis phase. Students should
understand that both are part of risk management, which identifies potential
vulnerabilities.
12. Define risk assessment as involving the association of a risk rating or score to an
15. Describe how an information security policy outlines how information should and will
be protected within an organization.
16. Explain the three different types of security policies that must be defined, according to
the National Institute for Standards and Technology (NIST):
a. General or enterprise InfoSec policy
17. Re-iterate the importance of a SETA program in preventing human error and human
failure related breaches to security.
18. Define the controls and safeguards terms as methods for protecting information against
attacks, and note the three different categories of controls:
a. Managerial controls, which are executed by the security administration of an
organization.
20. Stress the importance of addressing physical security needs, and discuss what can be
considered a physical resource.
21. The implementation phase should be explained as involving the acquisition of security
solutions and products, as well as the implementation and testing of products.
22. Outline the three steps that occur during the execution of the project plan:
23. List some of the different skill sets that might be involved in a development team:
a. Champion
24. Provide a list of the various roles involved in information security:
Management of Information Security, Fourth Edition 2-9
a. Chief information officer (CIO)
25. Explain how certifications can sometimes be sought after in order to verify an
individual’s proficiency in a subject.
26. Discuss the maintenance phase, in which information security systems are monitored,
tested, modified, updated, and repaired in accordance to an organization’s established
security policies.
27. Introduce students to an example maintenance model, and explain the five subject areas
that a maintenance model should address:
28. Explain to students some different ways to identify and fix vulnerabilities, such as
using documented vulnerability assessment procedures, and tracking discovered
vulnerabilities.
29. Describe a vulnerability assessment as analysis to determine an asset’s potential
30. Explain the roles of white-hat hackers, ethical hackers, tiger teams, or red teams in
penetration testing exercises.
Teaching
The Metasploit Framework is a tool that provides many different exploits that
computer networks. Many different methods exist for carrying out a denial of
Teaching
Management of Information Security, Fourth Edition 210
Quick Quiz 2
1. The ____________________ provides rules for the protection of information assets of
an organization.
2. True or False: Penetration testing occurs when a threat agent attacks an information
asset.
3. Business continuity plans, disaster recovery plans, and incident response plans are all
collectively part of __________ .
4. What is used to protect information from attacks by threats?
A. Buffer
B. Wall
C. Control
D. Screen
5. Why is the bottom-up approach less effective than the top-down approach?
A. Lack of technical support
B. Lack of management support
C. Lack of stakeholder support
D. Lack of stockholder support
Class Discussion Topics
1. Start a class discussion on the creation of a values statement. How does the values
statement dictate the goals of an organization?
Additional Projects
1. Task students with researching the Chief Information Officer (CIO) role. Students
should research current CIOs as well as job openings for CIOs. What are the job
requirements?
Management of Information Security, Fourth Edition 211
Additional Resources
1. Wikipedia article on penetration testing: