Definizione dei bisogni in termini di sicurezza informatica Definição das necessidades de termos de segurança informática 
Bestimmung des Bedarfs in Sachen Informatiksicherheit Définition des besoins en terme de sécurité informatique Definición de necesidades en términos de seguridad informática

Definition Phase

The definition phase for security needs is the first step towards implementing a security policy.

The goal consists in determining the organisation's needs by taking an inventory of the information system and then studying the different risks and threats that they represent in order to implement an appropriate security policy.

The definition phase is made up of three steps:

  • Identifying the needs
  • Analysing the risks
  • Defining the security policy

Identifying the Needs

The needs identification phase consists in first taking an inventory of the information system, notably of the following information:

  • People and jobs
  • Materials, servers and the services they provide
  • Network mapping (address map, physical and logical topologies, etc.)
  • List of the company's domain names
  • Communication infrastructure (routers, switches, etc.)
  • Sensative data

Risk Analysis

The risk analysis step consists in indexing the different risks encountered, estimating their probability and finally studying their impact.

The best way to analyse the impact of a threat consists in estimating the cost of the damages it would cause (e.g. an attack on a server or damage to vital company data).

On this basis, it might be interesting to draw up a table of risks and their potentiality (i.e. the probability that they might occur) by giving them staggered levels according to a scale to be defined. For example:

  • Unfounded (or improbable): the threat is groundless
  • Weak: the threat has little chance of occurring
  • Moderate: the threat is real
  • High: the threat has great chances of occurring

Defining the Security Policy

The security policy is the reference document that defines the security goals and the measures implemented to ensure that these goals are reached.

The security policy defines a number of rules, procedures and best practices that ensure a level of security that meets the needs of the organisation.

This document must be run like a project that brings together everyone from the users up to the highest part of the hierarchy so that it is accepted by all. Once the security policy has been written, the clauses concerning the employees must be sent to them so that the security policy can have the greatest impact.

Methods

Many methods exist that can be used to develop a security policy. Here is a non-exhaustive list of the main methods:



Last update on Thursday October 16, 2008 02:43:15 PM.This document entitled « Definition of Needs in Terms of IT Security » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.
Best answers for « Definition of Needs in Terms of IT Security » in :
Installing a SSH server on Ubuntu ShowInstalling a SSH server on Ubuntu Installation Connection An ssh server allows you to remotely access your machine. You'll have access to the remote console (equivalent to telnet, but secure) and the transfer of files (equivalent...
Disabling security alerts under Vista ShowDisabling security alerts under Vista If you are annoyed by the multiple Security Alert message, you can specify in which cases these messages will appear. The trick requires a modification of the registry, then it would be wise to save...
How to disable the security Center under windows XP? ShowHow to disable the security Center under windows XP? Intruduction Disable Alerts Turn off Windows Security Center Intruduction Windows security Center is a component that works under Windows XP service pack 2 for providing...
Download Eset Smart Security ShowAntivirus, antispyware, antispam, firewall: all-in-one! We cannot find a simple protection! Based on NOD32 antivirus, extremely little greedy in resources! Eset Smart Security is a protection solution to be tried!
Download SSH Secure Shell ShowSSH secure shell for workstations is a flexible client SSH allowing to connect in a secured way to remote applications. http://www.commentcamarche.net/faq/images/NHc6wz5jOYBhPXTis.png
Download Drivers Realtek High Definition Audio for 2000/XP ShowDescription Designed by RealTek Drivers Groups, the application is well known worldwide also. Very powerful to use, Driver Realtek High Definition Audio is an application that will allow you to have the best sound on your computer....
SD Card (Secure Digital) ShowSecure Digital Secure Digital memory (known as SD or SD Card) is a type of memory card created by Matsushita Electronic, SanDisk and Toshiba in January 2000. Secure Digital memory is a memory specifically developed to meet new safety requirements...
Security - Risk identification and types of hackers ShowWhat is a Hacker? The term "hacker" is often used to refer to a computer pirate. Victims of hacking on computer networks like to think they have been attacked by experienced hackers who have carefully studied their system and developed specific...
Viruses - Introduction to viruses ShowVirus A virus is a small computer program found within the body of another program which, when run, loads itself into the memory and carries out the instructions programmed by its author. The definition of a virus may be: « Any computer...