An Information-Oriented Examination of the Reference Object, the Subjects, Institutions, Instruments and Processes of Information Security.
Implementing information security in a business environment is complex and time-consuming. Many forces and influences contribute to the positive outcome of an information security project. Therefore it is an advantage to know as many of them as early as possible. These influences are examined and formalised in this dissertation and have been arranged as a framework. They have been integrated as a process.
There is one most important prerequisite to successfully manage information security: Getting top management commitment to implement information security and to free the resources needed to do so. Initially, this requires management to agree on an appropriate, uniquely formulated information security goal. Actual information security related goals can then be deduced from the general business policy. Business environment developments must be considered as well as internal requirements. An information security policy - informally in the beginning - begins to develop. This policy must be communicated within the enterprise as early and as consistently as possible and must be lived after exemplarily.
Based on this policy, an enterprise-wide organisation must be brought into life. It is needed to initialise and to support the execution of a corresponding information security project within the enterprise. This organisation, which can be lead by an Information Security Delegate, has the following tasks:
* To formulate, to formalise and to spread the information security policy,
* to split the overall project into individual, manageable parts and subjects, e.g. in accordance to department boundaries,
* to promote the co-operation of information security activities between existing institutions inside the enterprise and its integration into business processes,
* to supply strategic and tactical methodologies and procedures to implement information security within the individual departments,
* to co-ordinate the information security activities, most importantly when problems must be solved at a level superior to an individual project,
* to take care of, to provide advice for and to promote the individual information security projects,
* to collect know-how and to pass it on,
* to supply tools for information security administration, awareness promotion etc., and
* to check on implementation and results.
Furthermore, a role model has to be defined. It should describe the information security responsibilities, functions and authorities of each individual person in the enterprise. This model must be formulated in such a way that each person fits into at least one of the roles.
In the proposal formulated in this dissertation, it is the duty of one person per department to co-ordinate local implementation of information security (this role is called Information Security Co-ordinator). This person must guide a process covering the following activities:
* To set the boundaries of the investigation target, concerning width and depth. Setting the width boundary is done by the express inclusion or exclusion of parts of the object investigated. Setting the depth boundary is done by limiting the investigation to specified kinds of objects (information, hardware, software, co-workers etc.) and by restricting the requirements to be considered (availability, confidentiality, obligation etc.),
* to identify and to administer protection objects, possibly collecting additional characteristics (requirements on the individual objects, important risks, object values etc.),
* to carry out a general risk analysis to identify major risks which the protection objects are subject to,
* to carry out specific risk analysises for the more exact consideration of important risks,
* to select measures to reduce the identified risks,
* to discuss and to promote decisions on measures to reduce the identified risks, considering costs and setting deadlines,
* to co-ordinate the implementation of measures, and
* to check on implementation, done by the person in charge, by those affected, by the Information Security Delegate and by other parties.
These components (goal, organisation, role model, process) make up the Information Security Management Framework, which is presented in this dissertation. A short description can be found in chapter 1. A broad view is presented at the beginning of chapter 3 and it is described in detail in chapters 3 to 6. The framework looks at information security as a management function. It is deduced it from the approaches of Rühli [Rühli85] and Heinrich [Heinrich93]. Part I and II of this dissertation are structured according to these approaches:
* The foundation (chapter 2) identifies and defines terms an general information security goals and concepts,
* the reference object (chapter 3) defines which part of the enterprise must be selected for information security and how it must be split into parts,
* the elements of information security (chapter 4) cover institutions, motivations, specific goals and instruments,
* the activities of information security (chapter 5) describe the various information security subjects which can be applied to the parts of the reference model,
* the information security process (chapter 6) describes the procedure in four cycles with five phases each.
A framework like this has not been described yet in any known approach. The existing procedures, which have mostly proven useful in practice, are subjected to a detailed analysis nevertheless, in order to identify their strengths and weaknesses. Is it deduced from this analysis how a new procedure must be constituted, if it were to combine the strengths and to avoid the weaknesses.
This new procedure, called "ISIWAY 4", covers the four framework components and is defined step by step in chapter 8. ISIWAY 4 is the first of two ways in which the framework is put into concrete form. It defines the procedure to reach information security in four cycles (hence the 4 in ISIWAY 4), called Minimal Information Security, Appropriate Information Security, Risk-Related Information Security and Comprehensive Information Security. ISIWAY 4 will be subjected to the same detailed analysis as the existing procedures mentioned before, in order to explain how the requirements are fulfilled.
The requirements of the new procedure will are divided in the groups Initiation, Organisation, Implementation and Content. ISIWAY 4 has been designed to be adaptable and scalable. Another required property of ISIWAY is ease of use. In order to achieve this, the procedure must not be too complex. The full ISIWAY 4 procedure is complex, so a more simple version was designed, which can be applied in smaller projects, or which may serve as an introduction to the information security process and should be easier to learn. ISIWAY 1.5 is such a simplification. It will be introduced in chapter 10 and is the second way described here to put the Information Security Framework in concrete. Additionally, this procedure is fully supported by a tool named ISIGO 1.5. This tool is presented in chapter 9 and supports the execution of each step of the ISIWAY 1.5 procedure. In addition, it considers some items of the ISIWAY 4 procedure presented in chapter 8 and is based on structures of an overall data model, which is presented in chapter 9 under the title of ISIGO CENTRAL.
Thus, this dissertation offers a structured, broadly supported and detailed analysis of the information security problem field, defines an information security management framework as a general solution, contains two procedures named ISIWAY 4 and ISIWAY 1.5 which differ in complexity, and it supplies a corresponding tool named ISIGO 1.5.
Therefore, all components necessary to implement information security efficiently and effectively in a business environment have been presented in this dissertation. In particular, the framework developed here (part II) can be used as a basis for further work in the information security management field.