MgmtOfInfoSec 6e-Ch02 PR
MgmtOfInfoSec 6e-Ch02 PR
MgmtOfInfoSec 6e-Ch02 PR
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
1
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
Learning Objectives
Introduction
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
3
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
Introduction (Continued)
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
4
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Ethics in InfoSec
Chapter 02: Compliance: Law and Ethics
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
Ethics in InfoSec
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
6
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
7
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
8 8
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
9
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
10
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
11
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
12
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Professional Organizations
and Their Codes of Conduct
Chapter 02: Compliance: Law and Ethics
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
14
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
15
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
16
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
SANS
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
17
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
ISACA
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
18
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
19
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Information Security and Law
Chapter 02: Compliance: Law and Ethics
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
Types of Law
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
21
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
22
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
23
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
24
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
25
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
27
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
28
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
29
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
• The CSA charged the National Bureau of Standards (now NIST) and
the National Security Agency with the development of:
• Standards, guidelines, and associated methods and techniques for computer
systems
• Uniform standards and guidelines for most federal computer systems
• Technical, management, physical, and administrative standards and
guidelines for the cost-effective security and privacy of sensitive information
in federal computer systems
• Guidelines for use by operators of federal computer systems that contain
sensitive information in training their employees in security awareness and
accepted security practice
• Validation procedures for, and evaluation of the effectiveness of, standards
and guidelines through research and liaison with other government and
private agencies
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
30
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
Privacy Laws
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
31
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
32
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
33
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
34
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
35
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
36
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
37
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
40
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
Breach Laws
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
43
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
44
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
45
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
46
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
47
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
PCI DSS
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
49
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
50
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
51
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
52
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
• Because policies function like laws, they must be crafted with the
same care as laws to ensure that the policies are complete,
appropriate, and fairly applied to everyone in the workplace
• The key difference between policy and law is that while ignorance
of the law is not an excuse (ignorantia juris non excusat),
ignorance of policy is a viable defense, thus policies must be:
• Distributed to all individuals who are expected to comply with them
• Read by all employees
• Understood by all employees, with multilingual translations and translations
for visually impaired or low-literacy employees
• Acknowledged by the employee, usually by means of a signed consent form
• Uniformly enforced, with no special treatment for any group (e.g., executives)
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
53
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Organizational Liability and the
Management of Digital Forensics
Chapter 02: Compliance: Law and Ethics
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
55
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
57
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
Digital Forensics
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
60
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
61
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
62
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
63
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
64
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
65
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
66
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
67
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
68
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
69
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
Summary
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
70
distributed with a certain product or service or otherwise on a password-protected website for classroom use.
Management of Information Security, 6th ed. - Whitman & Mattord
Summary (Continued)
Summary (Continued)
© 2018 Cengage. May not be copied, scanned, or duplicated, in whole or in part, except for use as permitted in a license
72
distributed with a certain product or service or otherwise on a password-protected website for classroom use.