Starting a Security Program
For years, you’ve had security as an item on your to do list, but you’re not quite sure how to get started. Or maybe your organization has recently had an incident and has decided its time to improve their security and the task has fallen to you. Whatever the reason, we will look at some of the first steps towards creating an information security program, some helpful resources, and some high impact/low cost actions you can take to get the momentum going in the right direction. A guide to developing a cybersecurity program for NSF Science and Engineering Projects is hosted by TrustedCI.
Getting the ball rolling
The first step in having a security program is creating your Master Information Security Policies and Procedures document (MISPP). This is going to be your blueprint for everything that follows. The first part of the MISPP should define the purpose of your security program, whether that be to protect your organization’s reputation, protect its operational resources to enable its production goals, or protect its intellectual property. The MISPP also needs to define roles and delegate security responsibilities to those roles in your organization. Security responsibilities include things like, who can accept risk on behalf of the organization, who can make or accept changes to new or existing security policies, who can approve exceptions to existing policies, and who is in charge of handling incident response (see below).
The main body of the MISPP should define how security policies should be created, adopted and changed, how security policies should be enforced, and define general procedures for key security activities, such as Disaster Recovery, Incident Response, Password Policy and Data Handling and Classificiation, linking to other policy and procedure documents if available. When getting started you may only have a single sentence or two for each item, the important thing is to get moving in the right direction and build step by step.
TrustedCI provides an MISPP template to use as a starting point.
Incident Response Plan and Procedure
An Incident Response plan (IRP) is the second security document you should create. The MISPP might define what and incident is and who is responsible for executing incident response, but the IRP defines how that should be done, what roles various staff in your organization should play, and how to communicate information about the incident both internally and externally.
ResearchSOC has an upcoming webinar on developing an Incident Response Plan on June 25th. In this webinar you’ll learn key strategies for developing or improving your incident response to better suite the needs of your organization.
TrustedCI.org offers an incident response plan template that you may download here.
Maturing a Security Program
Once you have the building blocks of a information security program in place you can begin to build a mature program through the use of security exercises. Security exercises are a fantastic tool to test the readiness and effectiveness of your security program. ResearchSOC has a webinar available on-demand to help you learn how to implement and conduct regular security exercises as part of a maturing information security program.