180 likes | 309 Views
Defining the security Project. Presentation. Defining Security Project Scope. For security projects define the scope with the following in mind: Holistic vision Proactive approach Security risk management Critical success factors Constraints Corporate culture and policies.
E N D
Defining the security Project Presentation
Defining Security Project Scope • For security projects define the scope with the following in mind: • Holistic vision • Proactive approach • Security risk management • Critical success factors • Constraints • Corporate culture and policies
Defining Security Project Scope • Corporate security project plan or program • Provides a holistic vision to the enterprise security and strategy • All security projects must be in synch with the enterprise wide strategy • Focus on prevention vs. remediation • Proactive approach to security • Prevention is less costly than remediation
Defining Security Project Scope • Include the task to • Evaluate and prioritize security risks • Ecommerce applications have greater exposure to security issues than applications that run locally • Payment applications have much more serious security problems that informational sites • Security risk management strategy balances business and security risks as it has been reflected by the corporate security plan • Up-to-date practice of security risks management is built on the basis of threats modeling
Defining Security Project Scope • Ensure the critical success factors are in place • Executive support • More important for security projects than for any others • Security projects often are seen as “unnecessary burden” • User involvement • Needed to balance security and usability • Experienced project manager • Error or omissions in the area of security may cost a lot for the company business • Clearly defined project objectives • Identify the problem and the outcome • It will create the ground for defining the project objectives
Defining Security Project Scope • Critical success factors (cont.) • Shorter schedules, Multiple Milestones • Make the project monitoring and control easier • Clearly define project management processes • Allows better organization • Avoid confusions and misunderstanding • Standard infrastructure • Use standard components whenever possible • Use standard templates, images
Defining Security Project Scope • Apply security project constraints • Scope • Time • Cost • Quality
Defining Security Project Scope • Take into account the corporate culture and policies • Be aware about security policies • Follow security standards and guidelines
Defining Security Project Scope • Define Security Problem • Think in terms of CIA • What exactly is your problem? What is your priority? Is it confidentiality, or integrity, or availability? • Make a clear statement about what problem will be resolved
Example • New application stores credit card data on your database server. You are requested to protect data on the server • What exactly are the security concerns? • Software code • Data confidentiality, integrity • Unauthorized access, • Business continuity
Define Security Project • Define the outcome • What level of protection will be implemented? • Example • Best industry practice (OWASP, compliant to PCI-DSS)
Define Security Project • Define potential security solution • Develop the ideas about how the security problem can be resolved • Follow best industry practice recommendations
Define Security Project • Define the optimal security solution • Evaluate your options from the security outcome point of view – which one is better fit? • You may need to consult Risk Management department
Define Security Project • Apply constraints • Scope • Time • Money • People skill • Re-define your project in accordance to the constraints, but do not sacrifice security
Define Security Project • Identify the security project sponsor • CISO • CIO • CFO • Business VP • Operations VP
Example • When you define a sponsor think about what part of organization is most to benefit from the project implementation • Business improved – go to business people • Regulatory compliance – business or risk management • Technology improvements – CIO or CTO
Summary • Security project scope has been defined when you have understanding of • A security problem • A security outcome (must be improved!) • The optimal solution • Constraints (scope, time, cost, quality) • Project sponsor