Management of Information Security, Fourth Edition 5-1
Chapter 5
Developing the Security Program
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Management of Information Security, Fourth Edition 5-2
Lecture Notes
Overview
Chapter 5 starts by outlining how different sized organizations may structure their
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Explain the organizational approaches to information security
List and describe the functional components of an information security program
Teaching Tips
Introduction
1. Define an information security program as involving the structure and organization of
the effort to contain risks to the information assets of an organization.
Organizing for Security
1. Explain how organizational culture, size, security personnel budget, and security capital
budget influence how an information security program is structured.
Security in Large Organizations
1. Discuss how security is handled in large organizations, and note that they typically
organize different functions into different internal groups.
Management of Information Security, Fourth Edition 5-3
2. Provide students with the recommended approach for separation of functions into four
separate areas:
a. Functions performed by non-technology units outside the IT area of
3. Discuss the typical staffing capabilities of organizations that are large in size (more
than 1000 devices), and note that it is the CISO’s responsibility to ensure that InfoSec
functions are performed.
Security in Medium-Sized Organizations
1. Discuss with students the differences in staff organizations that occur in medium sized
organizations in comparison with large organizations, and note that many functions are
Security in Small Organizations
1. Provide students with information on the security challenges within small organizations
(with less than 100 systems to support), and note that this often requires a security
administrator that can manage the majority of the security tasks, with help from
assistants.
2. Explain that small organizations often lack sufficient policy, planning, or security
reduced anonymity of employees.
Teaching
Tip
Security in small organizations is often relaxed due to funding issues. However,
it is important to remain vigilant in security matters regardless of the size of an
Management of Information Security, Fourth Edition 5-4
Placing Information Security within an Organization
1. Describe where information security departments are typically placed in large
organizations, and note that these departments are headed by the CISO, who reports to
the CIO.
2. Emphasize that organizations should strive to find a place for the information security
Responsibilities Made Easy book.
Components of the Security Program
1. Explain that the strategic plan and the organization’s vision and mission statements
determine how an information security program will operate.
2. Describe Charles Cresson Wood’s recommendations on the formulation of mission
statements
3. Discuss the two documents from NIST that provide guidance for the development of an
InfoSec program:
b. SP 800-12 (An Introduction to Computer Security: The NIST Handbook)
4. List some of the different topics covered by the NIST Handbook:
a. Elements of computer security
g. Contingency planning
5. Discuss some of the essential InfoSec program elements that presented in the SP 800
14 and SP 800-12 documents, such as policy, risk management, awareness and training,
and audit trails.
Information Security Roles and Titles
1. Explain that information security positions can be classified into three types: those that
define, those that build, and those that administer.
2. Provide a list of the different categories that most security related responsibilities will
fall under:
a. CISCO or CSO
Teaching
The full SP 800-12 handbook is available through NIST online:
Management of Information Security, Fourth Edition 5-5
b. Security managers
Chief Information Security Officer
1. Discuss the primary responsibilities of a CISO, such as the assessment, management,
and implementation of a security program.
2. Make students aware of the fact that a CSO may have one or more physical security
Security Managers
1. Describe security managers as being accountable for the day-to-day operations of the
Security Administrators and Analysts
1. Describe a security administrator as a hybrid between a security technician and a
security manager, and note that they are typically responsible for operations related to
Security Technicians
1. Define a security technician as an individual who configures security related hardware,
such as firewalls and IDPSs, and explain that this is typically an entry level position.
Security Staffers and Watchstanders
Management of Information Security, Fourth Edition 5-6
1. Make students aware of security staffers, sometimes known as watchstanders, who
Security Consultants
1. Describe a security consultant as an independent expert in a specific aspect of InfoSec,
Security Officers and Investigators
1. Educate students about the existence of physical security and InfoSec program hybrids
Help Desk Personnel
1. Explain the role of a help desk employee in troubleshooting and diagnosing an issue
Quick Quiz 1
1. A(n) ____________________ is a type of specialized security administrator, and is
typically responsible for analyzing and designing security solutions in a specific
domain.
2. True or False: A CISO never reports to the CIO, and must always go through
management hierarchies.
3. Which security role is typically responsible for monitoring e-mail accounts and
instruction consoles?
A. Security technicians
B. Security administrators
C. Analysts
D. Watchstanders
4. Which NIST publication covers topics such as elements of computer security, roles and
responsibilities, and common threats?
A. SP 800-21
Management of Information Security, Fourth Edition 5-7
B. SP 800-12
C. SP 800-11
D. SP 800-01
5. An organization is considered to be medium-sized when it has approximately how
many devices?
A. Less than 100
B. More than 1000
C. More than 100, less than 1000
Answer: C
Implementing Security Education, Training, and Awareness
Programs
1. Reintroduce the security, education, training, and awareness (SETA) program, which is
designed to reduce the chances of accidental security breaches caused by various
human resources in an organization.
2. Discuss the three major benefits of a SETA program:
a. They can improve employee behavior
3. Emphasize the importance of employee accountability, and note that lack of
accountability increases the chance of organizational failure.
6. Discuss some of the features of SETA within an organization, and elaborate on their
delivery, and how outcomes are assessed.
Security Education
1. Describe some of the options that exist for security program training, such as NIST’s
2. Explain that InfoSec training must address two specific issues:
Management of Information Security, Fourth Edition 5-8
3. Provide students with information regarding the lack of information security specific
programs present in many InfoSec or computer security degrees, and note that more
specialized programs should be sought.
6. Describe the use of a knowledge map for guiding students in the right direction when
seeking specialized education for a given area within InfoSec, such as curriculum that
focuses on policy and planning, or in technical expertise.
7. List some of the different certifications available in information security, and explain
what job roles a specific certification may qualify a student for, such as managerial or
d. Global Information Security Officer (GISO)
Security Training
1. Explain that security training can be developed in house, or be outsourced. Note that
some industry training conferences can be subsidized.
2. Discuss some of the documents available for guiding the creation of SETA programs,
4. Explain that specialized training is more likely to be effective, and note the two
different methods for customizing training for users: by functional background, and by
skill level.
5. Discuss training for general users, which may include training on good security
Teaching
Tip
For a more detailed listing of information security certifications, see the
following link:
Management of Information Security, Fourth Edition 5-9
Training Techniques
1. Stress the need for good training methods, and educate students on the advice provided
by Charles Trepper in his “Training Developers More Efficiently” article.
department, an external agency, a professional trainer or consultant, or someone from
an accredited institution.
4. Discuss the NIST Handbook’s seven step methodology for implementing training:
Security Awareness
1. Introduce students to the concept of a security awareness program, which help an
organization’s employees realize the importance of security and consequences of its
failure, as well as remind users of procedures that must be followed.
2. Make students aware of some of the recommendations for the development of a
Program” article.
4. Describe how security awareness and training help to modify employee behavior by
making them aware of policy and the penalties for failure to comply with policy.
5. Re-iterate that failure to follow policy by management will ensure that no one follows
policy.
8. List some of the different security awareness components that can be used to improve
security awareness for little or no cost:
a. Videos
Management of Information Security, Fourth Edition 510
h. Bulletin boards
9. Explain to students that a security related newsletter can be a cost-effective to inform
10. Provide students with a list of items that would make good inclusions for a newsletter
11. Elaborate on the use of security posters, which can be used to remind employees about
security related issues. Discuss some of the keys for a good poster series:
12. Explain how a trinket program might be used to keep employees focused on
maintaining a secure environment, and list some types of trinkets that might be used:
a. Pens and pencils
13. Introduce students to information security awareness websites, such as Kennesaw State
University’s InfoSec web site.
14. Provide students with Scott Plous’s recommendations on the creation and maintenance
of an educational web site:
a. See what’s already out there
15. Point out the advantages of putting a site on an organization’s internal network for
access by organization employees only.
16. Discuss the possibility of having a guest speaker provide InfoSec knowledge to an
organization’s employees.
Quick Quiz 2
Teaching
See the following WikiHow link for tips on participating in Computer Security
Management of Information Security, Fourth Edition 511
1. The ____________________ is the responsibility of the CISO, and is designed to
reduce incidence of accidental security breaches by organization members.
2. True or False: It is the CISO’s responsibility to ensure that InfoSec functions are
performed within an organization.
3. The NIST __________ document describes training with emphasis on roles and results,
rather than fixed content.
4. All but which of the following is certification training recommended for a student
focusing on managerial information security?
A. Certified Information Systems Security Professional
B. Security+
C. Certified Information Security Manager
D. Global Information Security Officer
5. Which of the following is NOT a major benefit of SETA programs?
A. They enable the organization to hold employees accountable
B. They can inform members of the organization about where to report policy
violations
C. They can improve employee behavior
D. They can improve configuration rule security
Class Discussion Topics
1. Get students to discuss possible ways to influence and motivate employees within an
organization in regards to information security.
Additional Projects
1. Task students with searching for job openings related to information security, and have
students match job titles with their respective roles as they are described in this chapter.
2. Give students time to research some of the different information security education
Management of Information Security, Fourth Edition 512
Additional Resources
1. Blog article showing the most popular information security job titles: