The Information Technology is penetrating all walks of life. With the advent of internet and the web technologies, we can see and feel the reorientation of business transformations, business deliveries and electronic transactions handled and Electronic Delivery Systems undergoing massive transformation. As organizations have become more dependent on the networks and business transactions, external data sharing and simple day to day communications, the need drives the networks to be more transparent and accessible but also protected from illegal access and abuse. Today the current security solutions are basically comprised of multi-point products designed for an isolated task (such as detecting a virus, preventing an intrusion). This results in lack of interoperability, unmanageability and a higher cost of ownership. So integrated security is emerging as an effective approach to address the new challenges. This integrates multiple security technologies such as anti-virus, firewall intrusion and combines policy compliance management, service and support and advance research for more complete protection. The holistic addressing of security at each tier and of the network (i.e. client, server, gateway), the organizations are able to reduce cost, improve manageability, enhance performance, tighten security and reduce risk exposure.
The executive goals for reducing the total cost of ownership with improved security are as follows, a) Implementing solutions that ensure openly robust but yet secure network infrastructures to protect information assets and to ensure business continuity. b) Keeping pace with changing requirements of e-business for example (high-network availability, data integrity and privacy) under corresponding security threats. c) Meeting, logging, reporting, auditing and compliance requirements. d) Facing challenges with limited resources at lowest cost. e) Solutions that maximize employee productivity including that of IT department (for example ease of security solutions administration and management).
The integrated security, a new network approach is essential for integrity of various security challenges and exposure to various threats to be minimized by increasing security posture, operation efficiency of security functions, minimized impact of business and reducing total cost of ownership for providing more comprehensive secure information processing solutions for the business needs.
Security management involves tradeoffs The information assurance policies and procedures you implement should reflect the tradeoff between your aversion to risks and how much it costs to do something about them. You want that tradeoff analysis to be both rigorous and well reasoned to get the most for your money. The System Security Engineering Capability Maturity Model (SSE-CMM) provides an excellent framework for conducting those tradeoffs.
System Security Engineering Capability Maturity Model The SSE-CMM is a construct for analyzing your security needs. It is not an automated tool. It is both a model and a process. The model is owned by a community of 50 companies / agencies led by the U.S. National Security Agency (NSA) and the Canadian Communications Security Establishment (CSE). The model presents security engineering as a defined, mature, and measurable discipline.
The model and appraisal method enable: Capability-based assurance, that is, security/trustworthiness inferred from the maturity of processes focused investment in security engineering tools, training, process definition, management practices, and improvements based on risk assessment and available resources qualifying vendors, suppliers, and organizations to connect to a system
Five maturity levels There are five maturity levels of capability in the SSE-CMM . 1 (Performed Informally) is the lowest level of maturity, followed by 2 (Planned and Tracked), 3 (Well Defined), 4 (Quantitatively Controlled) and 5 (Continuously Improving) which is the highest. In order to sustain a higher level of maturity of capability, all of the requirements for the lower levels must also be sustained. The various System Security Process Areas in the SSE-CMM include, among others, specifying security needs, threat and risk assessment, administering security controls, managing configurations, planning overall technical efforts and improving the organisation’s Security Engineering Processes.
Security standards Apart from one described above, the Indian Standards body (BIS) has been working for adapting/developing information security standards for the last few years. India has evolved a new security management requirements standard that is also harmonized with the latest quality management standards in November’2002. This is one of the world class standards along with the information classification standard which has been adapted from the international standard IS14990 which talks about trusted secured systems classification and services requirements will enable the users to classify the information systems etc. on secure classification and also get it certified for the same using the information management certification standard IS15150.
The information systems security research is one of the visions of the Government to concentrate in the next few years to develop security techniques, security technologies and products to be used for facing new challenges using open media for transactions pertaining to Government, Industry and Business covering commercial, financial and administrative aspects. The security requirements are of dynamic phenomena and not a static phenomenon. The security management is no longer technology oriented but management oriented for effective implementation as well as, ascertaining information and systems as an asset of the organization. The information assurance involves people, processes and technology. The information assurance is risk management and not risk avoidance. It has to be customized for every organization based on various requirements which are static and dynamic and depending upon the risk and challenges they are facing is conducting, managing and transacting businesses within the country and across the globe.
The integrated security, a new network approach is essential for integrity of various security challenges and exposure to various threats to be minimized by increasing security posture, operation efficiency of security functions, minimized impact of business and reducing total cost of ownership for providing more comprehensive secure information processing solutions for the business needs.
For further information, write to ksdir@hub.nic.in