20141124_ED_514.01_Final_CDSE_OISSCS_DDD_v040413.pdf

PDF 263 KB Posted

Attached to
10 Graduate Courses Federal contract opportunity
Solicitation number
HS0021-15-R-0004
Issued by
Defense Counterintelligence and Security Agency

About this file

ED 514

View the file

Other files for this federal contract opportunity

Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Final (v1.1) Detailed Design Document Oversight of Information System Security and

Cybersecurity by DoD Security Specialists

Developed for

The Department of Defense (DoD) Defense Security Service (DSS)

Center for Development of Security Excellence (CDSE) Education Division

April 4, 2013

DSS CDSE Education Division Oversight of Information System Security and Cybersecurity Final Detailed Design Document

Document Version

Author Version Date Carney Inc. 1.0 1/8/2013 Carney Inc. 1.1 4/4/2013

Contents

1 Introduction

1.1 The Requirement

1.2 Purpose of the Detailed Design Document

1.3 Organization of This Document

2 Course Design

2.1 Course Description/Overview

2.2 Credits Conferred

2.3 Target Audience/Prerequisites

2.4 Student Outcomes/Objectives

2.5 Delivery Method

2.6 General Course Requirements

2.7 Grading

2.8 Course Textbooks

2.9 Course Outline

3 Content Outline

3.1 Week 1: The Security Environment

3.2 Week 2: Principles of Cybersecurity

3.3 Week 3: Cybersecurity Management Concepts

3.4 Week 4: Enterprise Roles and Structures

3.5 Week 5: Strategy and Strategic Planning

3.6 Week 6: Security Plans and Policies

3.7 Week 7: Laws and Regulations

3.8 Week 8: Security Standards and Controls

3.9 Week 9: Risk Management

3.10 Week 10: Security Metrics and Key Performance Indicators (KPIs)

3.11 Week 11: Physical Security and Environmental Events

3.12 Week 12: Contingency Planning

3.13 Week 13: Security Education, Training, and Awareness

3.14 Week 14: Managing Information Security Across the DoD Enterprise (I)

3.15 Week 15: Managing Information Security Across the DoD Enterprise (II)

3.16 Week 16: The Future of Cybersecurity

1 Introduction

1.1 The Requirement

The Defense Security Service (DSS) Center for Development of Security Excellence (CDSE) has undertaken, through its Education Division, the responsibility to provide graduate-level education to security professionals designed to develop the future security leaders for the Department of Defense (DoD).

The purpose of this project is to design and develop an advanced, semester-long course that will provide an educational opportunity for mid-career security specialists to gain in-depth knowledge and understanding of how to manage information security systems relevant to DoD programs. The course will develop each student’s ability to use this knowledge to become more effective as security leaders in the DoD. The course will be conducted via the Sakai Continuous Learning Environment (CLE) and will consist of readings, prerecorded lectures and presentations, asynchronous sessions, a discussion forum, written assignments, and midterm and final exams.

1.2 Purpose of the Detailed Design Document

The purpose of this Detailed Design Document is to convey the learning objectives, topic outlines, and planned assignments for each week of the course. It also proposes the grading schema the instructor will use. This document proposes the organization of content to be delivered throughout the 16-week semester and details the proposed instructional methods to be used for each week.

This detailed design will guide the development of the course materials.

1.3 Organization of This Document

The remainder of this Detailed Design Document is organized into several sections:

• An overview of the course

• A statement of the anticipated credits to be conferred

• A list of prerequisite courses, if applicable

• The terminal learning objectives of the course

• The delivery method(s) to be used

• General course requirements

• Grading scheme for the course

• A course outline showing how the course will unfold over the semester

• A content outline detailing the topics, instructional methods, and assignments for each week

Carney, Inc. Page 5 April 4, 2013

2 Course Design

2.1 Course Description/Overview

The ability to value and secure information within a modern enterprise—large or small— is a growing challenge. Threats to information security are global, persistent, and increasingly sophisticated. Long gone are the days when managers could hope to secure the enterprise through ad hoc means.

Effective information security at the enterprise level requires participation, planning, and practice. It is an ongoing effort that requires management and staff to work together from the same script. Fortunately, the information security community has developed a variety of resources, methods, and best practices to help modern enterprises address the challenge. Unfortunately, employing these tools demands a high degree of commitment, understanding, and skill—attributes that can be drawn away by other functions within the enterprise.

It is important to note as well that effective security is not achieved in stovepipes.

Ineffective physical security, for example, can undermine otherwise effective IT security, and vice versa. Effective security at the enterprise level requires the effective interaction of IT security, physical security, classification security, and so on—indeed, all branches of security must interact effectively as a system to achieve overall enterprise security.

This course is designed to teach mid-level security practitioners how to engage all functional levels within the enterprise to deliver information system security. To this end, the course addresses how to develop effective security policies and plans that align with the enterprise’s overall strategy and mission. Key to this is the ability to organize for security, measure security, and assess risk—topics which the course addresses in detail.

Additionally, the course considers external resources and requirements (standards and regulations) as well as supporting and complementary functions (business continuity and physical security). Each piece of the puzzle must be in place for information security to achieve its goals; adversaries will invariably find and exploit weak links.

The Department of Defense (DoD) is itself a massive enterprise, and security practitioners should understand the context of their activities within the overall DoD enterprise. Topics addressed on this count include the role of certification and accreditation (C&A) within the DoD enterprise, and the various roles, functions, and missions performed by cybersecurity organizations within DoD.

2.2 Credits Conferred

This course will be designed to equate to three credit hours at the graduate level. This course has not yet been reviewed by the American Council on Education.

2.3 Target Audience/Prerequisites

This course is intended for DoD civilian and military personnel who perform security leadership and management duties. It is assumed that all students will be prepared to take

Carney, Inc. Page 6 April 4, 2013 on graduate-level work in the security field. All students will be required to have achieved the Security Fundamentals Professional Certification (SFPC) under the DoD Security Professional Education Development Program (SPēD) or to have comparable fundamental knowledge of DoD security programs.

2.4 Student Outcomes/Objectives

At the end of this course, students will be expected to be able to

• Assess the current security landscape, including the nature of the threat, the general status of common vulnerabilities, and the likely consequences of security failures;

• Describe and assess the strengths and weaknesses of general cybersecurity models, including the CIA triad;

• Describe and appraise the interrelationships among elements that comprise a modern security system, including hardware, software, policies, and people;

• Assess and describe how all domains of security interact to achieve effective system-wide security at the enterprise level.

• Describe the interrelationships among security roles and responsibilities in a modern information-driven enterprise—to include interrelationships across security domains (IT, physical, classification, personnel, and so on);

• Assess the role of strategy and policy in determining the success of information security;

• Estimate the possible consequences of misaligning enterprise strategy, security policy, and security plans;

• Design a notional information security plan that incorporates relevant principles of lifecycle management;

• Explain the principles of risk and conduct a notional risk management exercise;

• Describe the role of good metrics and key performance indicators (KPIs) in security assessment and governance;

• Define and develop good information security metrics;

• Characterize the current legal and regulatory environment as it applies to cybersecurity;

• Identify, characterize, and evaluate the most common security standards and associated catalogues of security controls;

• Contrast the various approaches to security training and formulate a simple training agenda;

• Justify the need for business continuity planning and propose how to implement such a plan successfully within a modern enterprise;

• Compare and contrast logical and physical security;

• Appraise the current structure of cybersecurity roles across the DoD enterprise, including the roles and responsibilities of the relevant organizations;

Carney, Inc. Page 7 April 4, 2013

• Assess the strengths and weaknesses of the certification and accreditation approach to cybersecurity;

• Evaluate the trends and patterns that will determine the future state of cybersecurity.

2.5 Delivery Method

This is a graduate-level distance-learning course in assessing current and future security functions, technologies, and systems relevant to DoD programs. The course will consist of readings, prerecorded lectures and presentations, asynchronous sessions, participation in the discussion forum, graded research papers, and three quizzes.

Because this is a 3 credit hour equivalent course, the contact time over the 16 weeks should be approximately 30 hours. A typical week will include a 45 minute prerecorded lecture; it will be followed by either a quiz (about one hour duration to complete) or an on-line discussion forum. Generally a discussion will be based on instructor-provided discussion question(s) with each student providing a response and then commenting on other student inputs. This discussion format will constitute the remainder of the contact time for each lesson (for ten lessons).

Students should be prepared to critically discuss and debate the readings as well as analyze them for biases and multiple perspectives. Students should also be examining how other disciplines relate to the readings and be prepared to discuss this aspect.

The assigned course readings will draw from a variety of resources, such as authoritative readings (legislation, executive orders, policies, plans and strategies, and journals), implementation readings (government products that are responsive to or attempt to fulfill the requirements of authoritative documents), and external reviews (from the U.S.

Government Accountability Office, Congressional Research Service, or other agency or office). Students will be provided with a large number of open access and password protected sites yielding a tremendous number of research assets.

Students will also be expected to monitor current information security news and will be provided with links to news stories and events during the course. These will help inform the structured online discussions.

Students will be expected to do research at the graduate level in this course. To provide a substantial research capability to all students in the program, a number of internet-accessible research sites will be sent to each student prior to the first lesson. Students will receive information for signing on to approximately a dozen other research sites or databases relevant to security and defense studies; one example would be opening an account with the Defense Technical Information Center (DTIC). This will ensure that every student has more than enough resources to do the research expected in this course. The instructor may provide additional research sources or sites. Students are also encouraged to make use of library and research sources available to them in their own geographical area or through their own professional or academic networks (such as the Pentagon and NDU libraries).

Carney, Inc. Page 8 April 4, 2013

2.6 General Course Requirements

Class participation is both important and required. If, due to an emergency, students are not able to respond to a discussion promptly in the week it is assigned, they must contact the instructor by e-mail and will be expected to post their response in the following week.

Weekly assignments must be posted in the Sakai CLE by 2359 EST on the day they are due. It is expected that assignments will be submitted on time; however, it is recognized that students occasionally have serious problems that prevent work completion. If such a dilemma arises, students should contact the instructor in a timely fashion.

2.7 Grading

The following provides an approximate breakdown of how each assignment contributes to the overall performance in the class.

Class participation (via online discussion) 20% Quizzes (three/10% each) 30% Research papers (two/25% each) 50%

A letter grade will be assigned to each graded assignment, following the grading scale below:

A = 90% – 100% B = 80% – 89% C = 70% – 79% D = 60% – 69% F = 59% and below

Individual graded assignments with a score lower than 80% are acceptable; however, a student’s final grade at the end of the semester must be 80% or higher to pass the course.

Evaluation criteria for discussion question responses are listed below.

ASSIGNMENT EVALUATION CRITERIA

• Uses complete sentences

• Uses proper grammar structure

• Responses reflect depth of thought and critical thinking skills

• Integrates material from class/readings into responses

• Provides coherent and reasoned responses to all questions

• Integrates real world examples into responses

• Meets submission timeline

Evaluation criteria for each graded assignment aside from discussion questions, including the midterm and final exams, are listed below. Any assignment that receives a failing

Carney, Inc. Page 9 April 4, 2013 grade can be resubmitted within the following two weeks, but there will be no further extensions beyond this two-week period.

Assignment Evaluation Criteria A B C D F

Content Analysis and integration subject matter (readings, lecture, discussion, personal experience, etc.) is clear and convincing

Analysis and integration subject matter is clear and effective

Analysis and integration subject matter is underdeveloped

Analysis and integration subject matter is unsophisticated

Did not complete assignment

Did not complete assignment

Organization Paper shows exceptionally clear organization, purpose and focus

Paper shows good organization, purpose and focus

Paper lacks clear organization, purpose and focus

Paper is disorganized and confusing

Grammar Free of most grammatical errors

Some grammatical mistakes but generally shows successful grammar usage

Frequent grammatical errors

Appropriate grammatical knowledge not displayed for current language level

Overall Effect A strong overall effect with clear communication and support

A good overall effect with some support and adequate clarity

Paper struggles overall and does not give a coherent message

Paper has a poor overall effect and does not fulfill assignment

Timeliness Assignment turned in on time

Assignment turned in on time

Assignment turned in on time

Assignment turned in on time

Class Participation (20%):

To meet the requirement for sufficient contact time each week, there will be a combination of recorded lectures by the instructor along with online discussions by and among the students. This approach will be true for ten of the lessons. In a typical weekly lesson, the recorded presentation will be 45 minutes long (the student can listen to the presentation in smaller periods if desired). The students will then be presented one or two discussion questions for response to the instructor and then comment on the inputs from two other students. Each of these ten weekly online discussions is worth 20 points (on a 1000 point scale). The student response to the instructor is worth 4 or 8 points. Each comment to a fellow student is worth 3 or 6 points. The time to complete this online response/comment is one hour.

Quizzes (30%):

Carney, Inc. Page 10 April 4, 2013

Three quizzes will take place during the course at select intervals. Each quiz will be the equivalent of one hour of contact time and worth ten percent of the overall grade (100 points out of 1000). The first two quizzes will be short answer (choosing five out of seven questions) and the last will be multiple-choice.

Research Papers (50%):

Two research papers (approximately 10 pages each) will allow the students to delve more deeply into the challenges of designing and operating systems that help assure the confidentiality, integrity, and availability of information.

In the first paper, each student will prepare a notional security plan. This plan will address the issues discussed in the texts and the course and tailor the plan to a context defined by the student. The student will be expected to apply a superior level of analysis and demonstrate an ability to conduct outside research.

In the second paper, each student will conduct a notional risk assessment based on one of the risk approaches discussed in the course. This risk assessment should reflect real-world conditions but not represent a real-world system or enterprise. The student may wish to build on the context defined in the first paper but will not be required to do so.

Each paper will be worth 25% of the total course grade and may be written/submitted in stages. Outside research will be required and the students will be expected to employ the Chicago Manual of Style as the course style guide.

2.8 Course Textbooks

The following text will serve as the primary resource for this course:

Whitman, Michael E. and Herbert J. Mattord. Roadmap to Information Security for IT and Infosec Managers. Boston, MA:

Course Technology, 2011.

Additional readings for this course will draw from a variety of resources, such as authoritative readings (legislation, executive orders, policies, plans and strategies, and journals), implementation readings (government products that are responsive to or attempt to fulfill the requirements of authoritative documents), and external reviews (from the U.S. Government Accountability Office, Congressional Research Service, or other agency or office).

Supplemental readings may be selected from the following texts:

• Brotby, W. Krag. Information Security Management Metrics. Boca Raton, FL:

CRC Press, 2009.

Carney, Inc. Page 11 April 4, 2013

• Hayden, Lance. IT Security Metrics: A Practical Framework for Measuring Security and Protecting Data. New York: McGraw-Hill, 2010.

• Jacobs, Stuart. Engineering Information Security: The Application of Systems Engineering Concepts to Achieve Information Assurance. Hoboken, NJ: John Wiley & Sons, 2011.

Additional Primary Sources:

• CNSS, National Information Assurance Glossary.

• DoD IA Policy Chart.

Additional but not required texts:

• The Chicago Manual of Style, 16th Edition, Chicago: University of Chicago Press, 2010.

http://www.cnss.gov/Assets/pdf/cnssi_4009.pdf http://iac.dtic.mil/iatac/ia_policychart.html

Carney, Inc. Page 12 April 4, 2013

2.9 Course Outline

The following table outlines the 16-week course agenda.

Week Topics Method of instruction Assignments due

1 The Security Environment

• Threats, vulnerabilities, and consequences

• Advanced persistent threats

• The state of security today

• Why security matters to DoD

• Reading

• Presentation with notes and comments

Student introductions

2 Principles of Cybersecurity

• The interrelated components of the computing environment

• Cybersecurity models (the CIA triad, the star model, the Parkerian hexad)

• Variations on a theme: computer security, information security, and information assurance

• Reading

• Presentation with notes and comments

• Discussion

Discussion forum (DF) 1: Respond to instructor discussion questions and other student responses

3 Cybersecurity Management Concepts

• Security governance

• Management models, roles, and functions

• Reading

• Presentation with notes and comments

• Discussion

DF 2

4 Enterprise Roles and Structures

• Information security roles and positions

• Alternative enterprise structures and interfaces

• Reading

• Presentation with notes and comments

Quiz 1

5 Strategy and Strategic Planning

• Strategy

• Strategic planning and security strategy

• The information security lifecycle

• Architecting the enterprise

• Reading

• Presentation with notes and comments

• Discussion

DF3

6 Security Plans and Policies

• Levels of planning

• Planning misalignment

• The System Security Plan (SSP)

• Policy development and implementation

• Reading

• Presentation with notes and comments

DF4

Carney, Inc. Page 13 April 4, 2013

Week Topics Method of instruction

Assignments due

7 Laws and Regulatory Requirements

• Timeline of U.S. laws related to information security

• The Federal Information Security

Management Act (FISMA)

• Reading

• Presentation with notes and comments

• Discussion

DF5

8 Security Standards and Controls

• Security standards and controls

• Certification and accreditation

(C&A)

• Reading

• Presentation with notes and comments

Quiz 2

9 Risk Management

• Principles of risk

• Types of risk

• Risk strategies

• The Risk Management Framework

(RMF)

• Reading

• Presentation with notes and comments

• Discussion

DF 6

10 Security Metrics and Key Performance Indicators (KPIs)

• The challenge of security metrics

• What makes a good metric

• Approaches to security metrics

• Metrics and FISMA

• Reading

• Presentation with notes and

Research project 1

11 Physical Security and Environmental Events

• Physical and environmental threats

• Physical and environmental controls

• Reading

• Presentation with notes and comments

• Discussion

DF 7

12 Contingency Planning

• Developing a contingency plan

• Understanding the different types of contingency plan

• Responding to events

• Reading

• Presentation with notes and comments

• Discussion

DF 8

13 Security Education, Training, and Awareness

• Human factors in security

• Developing and implementing a security training plan

• Cross-domain training (IT and other security domains)

• Reading

• Presentation with notes and comments

DF 9

Carney, Inc. Page 14 April 4, 2013

Week Topics Method of instruction

Assignments due

14 Managing information security across the DoD enterprise (1)

• The purpose of certification and accreditation

• Trends in certification and accreditation

• Reading

• Presentation with notes and comments

• Discussion

Research project 2

15 Managing information security across the DoD enterprise (2)

• The strategic direction of DoD IT and information security

• Responsibilities within the DoD enterprise

• Reading

• Presentation with notes and comments

• Discussion

DF 10

16 The future of cybersecurity

• Key future uncertainties

• Possible future scenarios

• How to apply what you’ve learned

• Reading

• Presentation with notes and

Quiz 3

Carney, Inc. Page 15 April 4, 2013

3 Content Outline

3.1 Week 1: The Security Environment

Objective At the end of this session, the students should be able to

• Summarize the concepts of threat, vulnerability, and consequence and explain why they are important.

• Describe the current IT threat environment, including the concept of advanced persistent threats;

• Describe the need for information assurance across the DoD enterprise; and

• Recognize the course contributions potentially available from classmate’s professional backgrounds and current assignments.

Rationale In order to understand the security requirements and operational demands of IA management, the students should first understand the global security context in which information systems currently operate. This requires an understanding of the concepts of threat, vulnerability, and consequences and an appreciation of why security matters to DoD.

Discussion Questions

• How do the concepts of threat, vulnerability, and consequence differ, and how do they complement each other?

• What is an advanced persistent threat (APT), and why are security managers worried about the APT?

• What, if anything, is unique to the DoD security environment compared to the commercial environment?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Georgia Institute of Technology, Emerging Cyber Threats Report 2013.

• McAfee’s Third Quarter 2012 Threats Report.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Biographical sketch.

http://www.gtcybersecuritysummit.com/pdf/2013ThreatsReport.pdf http://www.gtcybersecuritysummit.com/pdf/2013ThreatsReport.pdf http://www.net-security.org/malware_news.php?id=2318

Carney, Inc. Page 16 April 4, 2013

Assignment for Next Session

• Discussion forum 1.

• Required readings for week 2.

3.2 Week 2: Principles of Cybersecurity

Objective At the end of this session, the students should be able to

• Describe the foundational principles of cybersecurity, including the CIA triad and its variants; and

• Describe the differences between computer security, information security, network security, and information assurance.

Rationale Cybersecurity is not new, although the environment is very dynamic.

Underlying cybersecurity is a set of well-established principles. These include the CIA triad and concepts of layered security. Not surprisingly, these principles share some elements with principles of security from other domains.

Discussion Questions

• What is the CIA triad, and what are some of its limitations?

• How do the Parkerian hexad and the star model enhance the traditional CIA triad?

• What is the concept of layered security, and how does it apply in the cyber domain?

• How do principles in cybersecurity and other security domains differ? How are they similar?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Whitman and Mattord, Roadmap to Information Security for IT and Infosec Managers, chapters 1–3.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Discussion forum 1.

Assignment for Next Session

• Discussion forum 2.

• Required readings for week 3.

Carney, Inc. Page 17 April 4, 2013

3.3 Week 3: Cybersecurity Management Concepts

Objective At the end of this session, the students should be able to

• Describe the concept and function of governance and how it relates to the management of information systems.

• Characterize general management functions and roles; and

• Describe how these functions and roles apply to information security management.

Rationale In this session we introduce the concept of information security governance and summarize the relevant concepts. We also discuss levels of management responsibility and outline how they apply to information security.

Discussion Questions

• What is governance? Why is it an issue, and how does it apply to information security?

• What are the typical management roles within an enterprise that relate to information security?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• NISTIR 7359, “Information Security Guide for Government Executives,” Jan. 2007.

• NIST SP 800-100, “Information Security Handbook: A Guide for Managers,” Oct. 2006 (browse).

• Whitman and Mattord, chapter 4.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Discussion forum 2.

Assignment for Next Session

• Quiz 1.

• Required readings for week 4.

3.4 Week 4: Enterprise Roles and Structures

Objective At the end of this session, the students should be able to

• Describe the variety of information security positions in a typical

Carney, Inc. Page 18 April 4, 2013 organization.

• Enumerate and describe the skills each position should embody;

• Describe the role of information security within the larger organization (particularly as it relates to traditional IT functions);

• Differentiate between the roles of the chief security officer, the security manager, and the security technician; and

• Describe the typical interfaces that exist between the security functions and other functions within an enterprise.

Rationale Security is an essential function in most modern enterprises. How security supports and interacts with other functions is an important consideration. Also worth considering is how the information security function is situated within the organization; several alternatives exist, and each brings with it advantages and disadvantages.

Discussion Questions

• How can security best be integrated across the enterprise given limited resources?

• How do IT and information security functions complement each other? In what ways do they conflict?

• What sort of weaknesses in the enterprise structure and behavior most undermine the security of the enterprise, and what can be done to avoid or overcome these weaknesses?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Whitman and Mattord, Roadmap to Information Security for IT and Infosec Managers, chapters 5–6.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Discussion forum 2.

Assignment for Next Session

• Discussion forum 3.

• Required readings for week 5.

3.5 Week 5: Strategy and Strategic Planning

Objective At the end of this session, the students should be able to

Carney, Inc. Page 19 April 4, 2013

• Describe how security strategy relates to enterprise strategy;

• Describe how an organization should go about developing a security strategy;

• Describe and characterize the phases of the security lifecycle;

• Explain the utility and value of enterprise architecting.

Rationale Ad hoc security leads to a host of problems. Security must be planned, and planning starts with strategy at the enterprise level. Security strategy should align with enterprise strategy. It also must address not only information security concerns but all security concerns across the enterprise and the lifecycles of the systems involved.

Discussion Questions

• Why is it important that information security strategy align with overall enterprise strategy and the strategies of other functional units? What consequences might follow misalignment?

• What perspectives might management adopt that run counter to a full lifecycle perspective? What problems could ensue?

• What is enterprise architecture and why how might an enterprise (and more specifically a security professional) apply it?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Review Whitman and Mattord, Roadmap to Information Security for IT and Infosec Managers, chapter 4.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Discussion forum 3.

Assignment for Next Session

• Discussion forum 4.

• Required readings for week 6.

3.6 Week 6: Security Plans and Policies

Objective At the end of this session, the students should be able to

• Describe and characterize the levels of security planning and cite examples at each level;

Carney, Inc. Page 20 April 4, 2013

• Describe the problem of planning misalignment;

• Summarize the purpose of the System Security Plan (SSP);

• Describe the purpose of security policy; and

• Explain the different types of security policies.

Rationale Information security planning is a complex task involving many different participants within the typical enterprise. Even if the enterprise develops a strong strategic plan, that plan must be translated effectively into a strong (and strongly aligned) information security strategic plan. This plan, in turn, must be translated into effective tactical and operational plans.

Discussion Questions

• How do the different levels of planning differ, and why is it important to align them?

• What sorts of pitfalls might attend security planning, and what consequences might ensue?

• What does a security policy entail, and how should an organization go about developing and implementing a solid security policy?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Review the policy section in NIST SP 800-14, “Generally Accepted Principles and Practices for Securing Information Technology Systems.”

• Review NIST SP 800-18 “Guide for Developing Security Plans for Federal Information Systems,” Feb. 2006.

• Whitman and Mattord, Roadmap to Information Security for IT and Infosec Managers, chapters 17 and 18.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Discussion forum 4.

Assignment for Next Session

• Discussion forum 5.

• Required readings for week 7.

Carney, Inc. Page 21 April 4, 2013

3.7 Week 7: Laws and Regulations

Objective At the end of this session, the students should be able to

• Identify and discuss the key legal and regulatory requirements that affect information security management; and

• Summarize the key requirements of the Federal Information

Security Management Act (FISMA) and describe how it affects the management of information systems.

Rationale An information security manager must be familiar with the legal and regulatory requirements that circumscribe both information security and privacy. While the requirements for (1) industry, (2) civilian government departments and agencies, and (3) national security elements in government sometimes differ, enough similarity exists to justify discussing the overall trend in legislation. Note that the material in this session is not legal advice and should not be taken as such.

Discussion Questions

• What sorts of tradeoffs must legislators weigh when considering information security legislation?

• What sorts of legal challenges are likely to emerge in the future as technology advances?

• Describe the relationship between FISMA and the NIST RMF and family of Special Publications.

• What advantages and disadvantages attend the certification and accreditation approach embodied in FISMA and other laws and regulations?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Browse the five publications in NIST’s Unified Information Security Framework.

• Read Whitman and Mattord, Roadmap to Information Security for IT and Infosec Managers, chapters 14 and 15.

Additional Reading

• Robinson, “U.S. Information Security Law, [Parts 1–4],” Symantec, 2010.

• To be updated with current news prior to session.

Assignments Discussion forum 5.

http://www.symantec.com/connect/articles/us-information-security-law-part-1

Carney, Inc. Page 22 April 4, 2013

Due

Assignment for Next Session

• Quiz 2.

• Required readings for week 8.

3.8 Week 8: Security Standards and Controls

Objective At the end of this session, the students should be able to

• Summarize the role of security models and standards, and explain why they are important to information security managers;

• Identify the similarities and differences between the security controls in ISO 27001, NIST 800, and DIACAP.

• Explain the purpose and function of the material in NISPOM

Chapter 8 and additional guidance to contractors from DSS

ODAA.

Rationale Current practice dictates the use of security standards and their associated controls. A variety of standards and control sets exist, and the IS manager should be familiar with the most common ones (ISO

270001, NIST 800-53, DIACAP).

Discussion Questions

• What are the advantages and disadvantages of the certification and accreditation (C&A) approach?

• Why are there so many different standards? What would the advantages or disadvantages of a single standard be?

• Posit some evolutionary paths forward from the current approach.

• From the perspective of the IS manager, what sorts of secondary benefits accrue from the C&A approach?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Browse NIST 800-53 Rev. 3 and Rev. 4.

• Browse the DIACAP controls and review NISPOM chapter 8.

• Read Whitman and Mattord, Roadmap to Information Security for

IT and Infosec Managers, chapter 12.

Additional Reading

• To be updated with current news prior to session.

Assignments Quiz 2.

Carney, Inc. Page 23 April 4, 2013

Due

Assignment for Next Session

• Discussion forum 6.

• Required readings for week 9.

3.9 Week 9: Risk Management

Objective At the end of this session, the students should be able to

• Describe the basic concepts of risk analysis;

• Explain the practice of risk management, including how an information security manager might employ the different risk strategies to address the different types of risk;

• Explain the limits of risk management; and

• Describe how the NIST Risk Management Framework (RMF) applies risk management to information security.

Rationale Risk management is a core function within the enterprise. Without effective risk management, enterprise and security management teams would not know what to defend, how much to commit to defense, and what to do when a risk trigger occurs. Risk management, when done well, addresses each of these concerns.

Discussion Questions

• What strategies exist to address risk, how do they differ, and when might you choose one strategy over another?

• What types of risk exist, and why should the information security manager be aware of all of them?

• What pitfalls do risk analysts face, and how can they avoid these pitfalls?

• How has the federal approach to information security shifted to more of a risk-driven one?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Read NIST SP 800-37, “Guide for Applying the Risk Management Framework to Federal Information Systems, Rev. 1, Feb. 2010.

• Read Whitman and Mattord, Roadmap to Information Security for IT and Infosec Managers, chapters 8–10.

Carney, Inc. Page 24 April 4, 2013

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Discussion forum 6.

Assignment for Next Session

• Research project 1.

• Required readings for week 10.

3.10 Week 10: Security Metrics and Key Performance Indicators (KPIs)

Objective At the end of this session, the students should be able to

• Describe the key concepts and purpose of security measurement;

• Explain why metrics are important to both risk management and governance;

• Explain the challenges and opportunities involved with information security metrics; and

• Differentiate between good and bad metrics.

Rationale A classic management adage suggests that you must measure something in order to manage it. This is certainly (mostly) true of information security, where the community continues to research metrics and associated methodologies. Part of the challenge remains the challenge of measuring the human side of security.

Discussion Questions

• Do metrics for governance and risk management differ? If so, how?

• How can you differentiate between a good and a poor metric?

• Can you identify any important aspects of information security that can’t be measured effectively? If so, think about ways to measure these aspects directly or indirectly.

• What metrics are used to measure the effect of FISMA? What do these metrics indicate?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Carney, Inc. Page 25 April 4, 2013

Required Reading

• NIST SP 800-55, Rev. 1, “Performance Measurement Guide for Information Security,” July 2008.

• NISTIR 7564, “Directions in Security Metrics Research,” April 2009.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Research project 1.

Assignment for Next Session

• Discussion forum 7.

• Required readings for week 11.

3.11 Week 11: Physical Security and Environmental Events

Objective At the end of this session, the students should be able to

• Summarize why physical and environmental security are critical to information security;

• Identify some important connections and dependencies between information and physical security;

• Summarize the roles and responsibilities associated with the physical security function within the enterprise; and

• Describe and characterize common physical security controls.

Rationale Information security without a sufficiently supportive level of physical security (to include both malicious and natural threats) is still inadequate security. The two domains are supportive and must be treated as such. This of course requires that the functions, roles, and responsibilities across the two domains be coordinated. To achieve this, information and physical security professionals must be able to talk and sometimes even work across domains.

Discussion Questions

• Why does a discussion of information assurance necessarily involve a discussion of physical security?

• How might you improve the interface between physical and information security (technologically, functionally, and organizationally)?

• How do the cultures, perceptions, and skill sets of the information security and physical security domains typically differ, and how might these differences affect security within the enterprise?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Carney, Inc. Page 26 April 4, 2013

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Review relevant controls in DoDI 8500.02 and NIST 800-53.

• Read Whitman and Mattord, Roadmap to Information Security for

IT and Infosec Managers, chapter 33.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Discussion forum 7.

Assignment for Next Session

• Discussion forum 8.

• Required readings for week 12.

3.12 Week 12: Contingency Planning

Objective At the end of this session, the students should be able to

• Differentiate between incident response, disaster recovery, and business continuity plans;

• Describe the roles and responsibilities associated with each of these types of plans; and

• Describe the factors that determine the level and type of planning required for the enterprise.

Rationale Sometimes things go wrong, and sometimes they go very wrong. For the cases when things go very wrong, it is essential to have response planning in place. Such planning can come in different flavors, depending on the size and mission of the organization and the type of discontinuity anticipated.

Discussion Questions

• In what ways does the contingency planning function require the information security manager to interface with other functional managers within the organization?

• If you had $1 to spend on incident response, disaster recovery, and business continuity planning, how would you allocate your budget? Justify your decision.

• Posit some of the events that might trigger a disaster recovery or business continuity plan. Assess these using a risk-driven perspective (probability x consequence).

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

Carney, Inc. Page 27 April 4, 2013

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Read NIST 800-34, Rev. 1, “Contingency Planning Guide for Federal Information Systems” chapters 1–3.

• Read Whitman and Mattord, Roadmap to Information Security for IT and Infosec Managers chapters 21–24.

• Review relevant controls in DoDI 8500.02 and NIST 800-53.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Discussion forum 8.

Assignment for Next Session

• Discussion forum 9.

• Required readings for week 13.

3.13 Week 13: Security Education, Training, and Awareness

Objective At the end of this session, the students should be able to

• Explain how human factors affect information security positively and negatively;

• Discuss the principles that inform security training and awareness;

• Differentiate between education, training, and awareness; and

• Identify and summarize the main points that security education, training, and awareness should address.

Rationale While security technologies are an important part of maintaining a secure enterprise, human factors are just as important (some would argue more important). Training staff and sustaining security awareness can be expensive, however, and IS managers must consider carefully how to prioritize their SETA efforts in order to achieve maximum effect.

Discussion Questions

• Consider the SETA programs you have participated in. Were they effective? Why or why not?

• If you had $1 to spend on information security education, training, and awareness, how would you allocate your budget? Justify your decision.

• If you had $1 to spend on all security education, training, and http://csrc.nist.gov/publications/nistpubs/800-34-rev1/sp800-34-rev1_errata-Nov11-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-34-rev1/sp800-34-rev1_errata-Nov11-2010.pdf

Carney, Inc. Page 28 April 4, 2013 awareness, how would you allocate your budget? Justify your decision.

• Could money allocated to training be better spent on other aspects of security?

Class Agenda • PowerPoint presentation with notes and comments (45 minutes).

• Online discussion (75 minutes).

Class Activity Following the recorded presentation, the students will have two assigned discussion questions to pursue with commentary. Each question will be worth six points and each student will comment on another student response for four points. Total discussion is worth 20 points.

Required Reading

• Read NIST SP 800-50, Building an Information Technology Security Awareness and Training Program (2003).

• Read Schneier, “Security Awareness Training,” Schneier on Security, 27 March 2013.

• Read Whitman and Mattord, Roadmap to Information Security for IT and Infosec Managers, chapter 20.

Additional Reading

• To be updated with current news prior to session.

Assignments Due

Discussion forum 9.

Assignment for Next Session

• Research project 2.

• Required readings for week 14.

3.14 Week 14: Managing Information Security Across the DoD Enterprise (I)

Objective At the end of this session, the students should be able to

• Describe the purpose of certification and accreditation (C&A) within the Federal enterprise and, more specifically, within DoD;

• Summarize trends in certification and accreditation (C&A) from

DITSCAP through RMF; and

• Discuss possible alternatives to current C&A approaches.

http://www.schneier.com/blog/archives/2013/03/security_awaren_1.html

Carney, Inc. Page 29 April 4, 2013

Rationale The Federal enterprise currently employs a well-established C&A approach to information security. (This approach is embedded in the standards and controls discussed in week 8.) DoD is planning to move from DIACAP to RMF, which will make the DoD terms and processes more consistent with the rest of the Federal government but will continue the basic C&A…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .