Management of Information Security, Fourth Edition 7-1
Chapter 7
Security Management Practices
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Management of Information Security, Fourth Edition 7-2
Lecture Notes
Overview
In Chapter 7, students are introduced to information security management practices,
specifically involving benchmarking and baselining. The use of security metrics and
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
List the elements of key information security management practices
Teaching Tips
Introduction
1. Describe value proposition as the attempt to get the most value out of a provided level
of investment.
Benchmarking
1. Define benchmarking as the use of a similar organization’s practices in order to create a
blueprint for security.
2. Point out that using an example organization will not help with the implementation of
standards are often called gold standards.
Standards of Due Care/Due Diligence
1. Explain standard of due care, or due care, as a stipulated minimum level of security
Management of Information Security, Fourth Edition 7-3
3. Elaborate on the difficulty of implementing multiple recommended security practices at
once, and provide students with F. M. Avolio’s quote: “Good security now is better
Recommended Security Practices
1. Describe recommended business practices as involving the use of security efforts to
provide a superior level of performance, whereas best security practices (BSPs) are
efforts that are considered best in the industry.
Selecting Recommended Practices
1. Explain how industries that are regulated by laws and standards must comply with
regulatory or industry guidelines in their security practices.
3. Reiterate the use of NIST’s documents in establishing security practices, and introduce
4. Make students aware of some other sources of recommended security practices from
different vendors, such as Microsoft, Oracle, and Cisco.
Limitations to Benchmarking and Recommended Practices
1. Students should understand that organizations often do not disclose security practices,
and may not disclose breaches either.
2. Introduce the Information Systems Security Association (ISSA) as a professional
Teaching
Tip
Microsoft’s enterprise security best practices can be found at the following
TechNet page:
Management of Information Security, Fourth Edition 7-4
Baselining
1. Describe a baseline as an assessment of the performance of some action or process, and
Support for Benchmarks and Baselines
1. Explain that baselining and benchmark information does not provide as much
information on design and implementation as a complete methodology would.
2. List some of the different NIST publications written for baselining activities:
a. SP 800-27 Rev. A: Engineering Principles for Information Technology Security
3. Explain to students how the CERT website provides information on security practices
and implementations that can be used to develop a methodology.
4. Provide information on the seminars and classes offered by ISACA and IAPSC on
recommended security best practices.
5. List the 12 questions published by the Gartner Group that can be used for assessment of
Performance Measurement in InfoSec Management
1. Explain how costs, benefits, and performance of an information security program
should be measured for success.
InfoSec Performance Management
1. Define InfoSec performance management as the process of designing, implementing,
and managing the use of collected data elements to determine security program
Teaching
Tip
For an example of an IT security baseline, see the University of Wisconsin-
Madison page for OCIS Departmental IT Security Baseline:
Management of Information Security, Fourth Edition 7-5
4. List some of the different factors that should be considered during development and
implementation of an InfoSec program, as recommended by NIST’s SP 800-55 Rev. 1
document.
5. List the four factors critical to the success of an InfoSec performance program, as noted
by NIST’s SP800-55 Rev. 1 document:
Information Security Metrics
1. Define the use of metrics as a way to gather more granular, detailed measurements.
Building the Performance Measurement Program
1. Educate students about the different benefits of using InfoSec performance
measurements, as outlined by SP 800-55 Rev. 1.
2. Note that one of the most popular references that support the development of process
Specifying InfoSec Measurements
1. Emphasize the importance of determining exactly what will be measured during the
measurement process.
Teaching
Computer World article on Capability Maturity Model Integration:
Management of Information Security, Fourth Edition 7-6
Quick Quiz 1
1. The process of designing, implementing, and managing the use of collected data
elements to determine the effectiveness of a security program is known as
____________________.
2. True or False: An organization that works within an industry regulated by laws and
standards is required to meet regulatory or industry guidelines in security practices.
3. All but which of the following is one of the four factors critical to success of an InfoSec
program, as listed by SP 800-55 Rev. 1?
A. Actions-oriented measurement analysis
B. Strong upper-level management support
C. Practical InfoSec policies and procedures
D. Quantifiable performance measurements
4. Which NIST document covers basic engineering principles regarding security
baselines?
A. SP 800-27
B. SP 800-53
C. SP 800-53A
D. SP 800-11
5. What term below is used to describe security efforts that are considered among the best
in an industry?
A. Standard of due care
B. Standard of due diligence
C. Recommended business practices
D. Best security practices
Collecting InfoSec Measurements
1. Emphasize the necessity of establishing the how, when, where, and who questions of
metrics collection once an organization has determined what to measure.
2. Discuss the difference between macro-focus measurements and micro-focus
Management of Information Security, Fourth Edition 7-7
4. Describe how performance targets can be used to measure progress towards a specific
goal, as well as determine program success. Make students aware of how performance
Implementing InfoSec Performance Measurement
1. Explain to students that performance measurement is a continuous improvement
operation, and that collection of measurement data should part of standard operating
procedures.
2. Discuss the procedures for performance measurement as recommended by NIST SP
800-55 Rev. 1, and discuss the six subordinate tasks involved:
Reporting InfoSec Performance Measurements
1. Educate students on the importance of proper context for measurements, as well as
Trends in Certification and Accreditation
1. Define accreditation as the authorization of an IT system to process, store, or transmit
information.
2. Certification should be explained as an assessment of both technical and nontechnical
Management of Information Security, Fourth Edition 7-8
NIST SP 800-37 Rev. 1: Guide for Applying the Risk Management
Framework to Federal Information Systems: A security Life Cycle
Approach
1. Teach students about the Risk Management Framework (RMF) that is outlined within
3. Discuss the six step process used by the RMF, as shown in NIST SP 800-37 Rev. 1:
a. Categorize
4. Explain that steps 4 and 5 replaced the C&A approach that was previously used for
federal information systems.
5. Make students aware of how step 4 entails the development of a plan to assess security
controls currently in place.
6. Step 5 should be discussed as involving the authorization of information systems to
Quick Quiz 2
1. The best recommended practices are sometimes known as ____________________.
2. True or False: Performance targets are often a hindrance to effective security.
3. The __________ is a set of recommended or best practices for organizations using
payment cards.
4. Which two steps within the Risk Management Framework replaced the C&A approach?
Teaching
See the following link for NIST’s page on the Risk Management Framework:
Management of Information Security, Fourth Edition 7-9
A. Steps 1 (categorize) & 2 (select)
B. Steps 2 (select) & 3 (implement)
C. Steps 3 (implement) & 4 (assess)
D. Steps 4 (assess) & 5 (authorize)
5. In security management, which term describes a comprehensive assessment of both
technical and nontechnical protection strategies for a particular system?
A. Verification
B. Accreditation
C. Certification
D. Authorization
Class Discussion Topics
1. Start a class discussion on the use of performance metrics in measuring security
2. Get students to discuss why regulated industries should be required to follow security
Additional Projects
2. Provide students with a set of performance measurements, and then task them with the
Additional Resources
1. Information on the PCI DSS standard:
2. Forbes article on the implementation of a risk management framework for health