IT Security Management: Difference between revisions

From IT Process Wiki
No edit summary
 
(7 intermediate revisions by the same user not shown)
Line 1: Line 1:
<seo metakeywords="information security management, itil security management, security management itil, itil security management process, security management process" metadescription="Information Security Management: ITIL process definition - Sub-processes - Terms - Additional information on Information Security Management." />
<itpmch><title>Information Security Management | IT Process Wiki</title>
<meta name="keywords" content="information security management, itil security management, security management itil, itil security management process, security management process" />
<meta name="description" content="Information Security Management aims to ensure the confidentiality, integrity and availability of an organization's information, data and IT services. ITIL Security Management usually forms part of an organizational approach to security management which has a wider scope than the IT Service Provider." />
<meta property="og:url" content="https://wiki.en.it-processmaps.com/index.php/IT_Security_Management" />
<meta property="og:title" content="Information Security Management | IT Process Wiki" />
<meta property="og:description" content="Information Security Management aims to ensure the confidentiality, integrity and availability of an organization's information, data and IT services. ITIL Security Management usually forms part of an organizational approach to security management which has a wider scope than the IT Service Provider." />
<meta property="og:site_name" content="IT Process Wiki - the ITIL&#174; Wiki">
<meta property="og:type" content="article" />
<meta property="article:publisher" content="https://www.facebook.com/itprocessmaps" />
<meta property="fb:admins" content="100002035253209" />
<meta property="fb:admins" content="100002592864414" />
<meta property="og:image" content="https://wiki.en.it-processmaps.com/images/e/e7/Itil-security-management.jpg" />
<meta property="og:image:width" content="1200" />
<meta property="og:image:height" content="1200" />
<link href="https://plus.google.com/108613479011811316823/posts" rel="publisher" />
</itpmch>
<imagemap>
<imagemap>
Image:ITIL-Wiki-de-es.jpg|DE - ES - Information Security Management|100px
Image:ITIL-Wiki-de-es.jpg|right|DE - ES - Information Security Management|163px
rect 0 0 50 30 [https://wiki.de.it-processmaps.com/index.php/IT_Security_Management diese Seite auf Deutsch]
rect 81 0 114 36 [https://wiki.de.it-processmaps.com/index.php/IT_Security_Management diese Seite auf Deutsch]
rect 50 0 100 30 [https://wiki.es.it-processmaps.com/index.php/ITIL_Gestion_de_la_Seguridad_de_TI esta página en español]
rect 115 0 163 36 [https://wiki.es.it-processmaps.com/index.php/ITIL_Gestion_de_la_Seguridad_de_TI esta página en español]
desc none
desc none
</imagemap>
</imagemap>
<br style="clear:both;"/>
<br style="clear:both;"/>


<p>&nbsp;</p>
'''<span id="Overview">Objective:</span>''' <html><span id="md-webpage-description" itemprop="description"><i>Information Security Management</i> aims to ensure the confidentiality, integrity and availability of an organization's information, data and IT services. ITIL Security Management usually forms part of an organizational approach to security management which has a wider scope than the IT Service Provider.</span></p>
 
<p><b>Part of</b>: <a href="https://wiki.en.it-processmaps.com/index.php/ITIL_Service_Design" title="ITIL Service Design">Service Design</a></html>
==<span id="Information Security Management">Overview</span>==
 
'''Objective''':  ''Information Security Management'' aims to ensure the confidentiality, integrity and availability of an organization's information, data and IT services. ITIL Security Management usually forms part of an organizational approach to security management which has a wider scope than the IT Service Provider.
 
'''Part of''': [[ITIL V3 Service Design|Service Design]]


'''Process Owner''': [[IT Security Management#Information Security Manager|Information Security Manager]]
'''Process Owner''': [[IT Security Management#Information Security Manager|Information Security Manager]]
Line 20: Line 30:
<p>&nbsp;</p>
<p>&nbsp;</p>


== Process Description ==
==Process Description==


ITIL V3 treats Information Security Management as part of the Service Design core volume, resulting in a better integration of this process into the Service Lifecycle (the previous ITIL version provided guidance on Security Management in a separate book). The process was updated to account for new information security concerns.
ITIL V3 treats Information Security Management as part of the Service Design core volume, resulting in a better integration of this process into the Service Lifecycle (the previous ITIL version provided guidance on Security Management in a separate book).  
[[Image:Itil-security-management.jpg|right|thumb|500px|alt=Information Security Management ITIL|link=https://wiki.en.it-processmaps.com/index.php/File:Itil-security-management.jpg|[https://wiki.en.it-processmaps.com/images/pdf/process_overview_it_security_management_itilv3.pdf ITIL Security Management]]]
 
The process has been updated to account for new information security concerns.


[[Image:Itil-security-management.jpg|right|thumb|375px|alt=Information Security Management ITIL|[https://wiki.en.it-processmaps.com/images/pdf/process_overview_it_security_management_itilv3.pdf ITIL Security Management]]]
ITIL does not provide a detailed explanation of all aspects of Information Security Management, as there are dedicated and more detailed standards available (see, for example, ISO 27001). Rather, ITIL highlights the most important activities and assists in identifying interfaces with other Service Management processes.
ITIL does not provide a detailed explanation of all aspects of Information Security Management, as there are dedicated and more detailed standards available (see, for example, ISO 27001). Rather, ITIL highlights the most important activities and assists in identifying interfaces with other Service Management processes.


Following the introduction of Design Coordination in '''''ITIL 2011''''' the information flows have been adapted. The process overview of [[Media:Itil-security-management.jpg|ITIL Security Management (.JPG)]] is showing the most important interfaces (see Figure 1).
Following the introduction of Design Coordination in ITIL 2011 the information flows have been adapted. The process overview of [[Media:Itil-security-management.jpg|ITIL Security Management (.JPG)]] shows the key information flows (see fig. 1).
 
<p>&nbsp;</p>
 
== Sub-Processes ==
 
These are the Information Management sub-processes and their process objectives:
 
<p>&nbsp;</p>
 
;<span id="ITIL Security Management Controls">Design of Security Controls</span>
:Process Objective: To design appropriate technical and organizational measures in order to ensure the confidentiality, integrity, security and availability of an organization's assets, information, data and services.
 
;<span="ITIL Security Management Testing">Security Testing</span>
:Process Objective: To make sure that all security mechanisms are subject to regular [[IT Security Management#Test Report|testing]].
 
;<span id="ITIL Security Management Incidents">Management of Security Incidents</span>
:Process Objective: To detect and fight attacks and intrusions, and to minimize the damage incurred by security breaches.
 
;<span id="ITIL Security Management Review">Security Review</span>
:Process Objective: To review if security measures and procedures are still in line with risk perceptions from the business side, and to verify if those measures and procedures are regularly maintained and tested.
 
<p>&nbsp;</p>
 
== Definitions ==


The following ITIL terms and acronyms (''information objects'') are used in ITIL Security Management to represent process outputs and inputs:
[[ITIL 4]] refers to 'Information Security Management' as a [[ITIL_4#General_management_practices|general management practice]].
<p style="clear:both;">&nbsp;</p>


<p>&nbsp;</p>
==Sub-Processes==


;<span id="Availability-ITSCM-Security-Testing-Schedule">Availability/ ITSCM/ Security Testing Schedule</span>
<html><div itemscope="itemscope" itemtype="https://schema.org/ItemList"><!-- define schema.org/ItemList -->
:A schedule for the [[IT Security Management#ITIL Security Management Testing|regular testing]] of all availability, continuity and security mechanisms, jointly maintained by [[Availability Management|Availability]], [[IT Service Continuity Management|IT Service Continuity]] and [[IT Security Management|Information Security Management]].
<meta itemprop="itemListOrder" content="Ascending" />
<p><span itemprop="name" content="Security Management sub-processes:">These are the <strong class="selflink">Information Management</strong> sub-processes and their process objectives:</span>
</p>
<p><b><span id="ITIL_Security_Management_Controls" itemprop="itemListElement">Design of Security Controls</span></b>
</p>
<ul><li itemprop="description">Process Objective: To design appropriate technical and organizational measures in order to ensure the confidentiality, integrity, security and availability of an organization's assets, information, data and services.
</li></ul>
<p><b><span id="ITIL_Security_Management_Testing" itemprop="itemListElement">Security Testing</span></b>
</p>
<ul><li itemprop="description">Process Objective: To make sure that all security mechanisms are subject to regular <a href="/index.php/IT_Security_Management#Test_Report" title="IT Security Management">testing</a>.
</li></ul>
<p><b><span id="ITIL_Security_Management_Incidents" itemprop="itemListElement">Management of Security Incidents</span></b>
</p>
<ul><li itemprop="description">Process Objective: To detect and fight attacks and intrusions, and to minimize the damage incurred by security breaches.
</li></ul>
<p><b><span id="ITIL_Security_Management_Review" itemprop="itemListElement">Security Review</span></b>
</p>
<ul><li itemprop="description">Process Objective: To review if security measures and procedures are still in line with risk perceptions from the business side, and to verify if those measures and procedures are regularly maintained and tested.
</li></ul>
</div><!-- end of schema.org/ItemList --><p></html>


;<span id="ITIL Security Management Rules">Event Filtering and Correlation Rules</span>
==Definitions==
:Rules and criteria used to determine if an Event is significant and to decide upon an appropriate response. Event Filtering and Correlation Rules are typically used by Event Monitoring systems. Some of those rules are defined during the Service Design stage, for example to ensure that Events are triggered when the required service availability is endangered.
: ''Note: The output "Event Filtering and Correlation Rules" has been added in ITIL 2011, to emphasize that (some) Event filtering and correlation rules should be designed by Information Security Management to support the detection of security issues.''


;<span id="ITIL Security Policy">Information Security Policy</span>
<html><div itemscope="itemscope" itemtype="https://schema.org/ItemList"><!-- define schema.org/ItemList -->
:The Information Security Management Policy describes and communicates the organization's approach to managing information security. It includes references to more specific [[IT Security Management#Underpinning-Information-Security-Policy|Underpinning Information Security Policies]] which, for example, set binding rules for the use of systems and information.  
<meta itemprop="itemListOrder" content="Ascending" />
<p><span itemprop="name">The following <a href="/index.php/ITIL_Glossary#ITIL_Glossary_A-Z" title="ITIL Glossary">ITIL terms and acronyms</a> (<i>information objects</i>) are used in the Security Management process to represent process outputs and inputs:</span>
</p>
<p><b><span id="Availability-ITSCM-Security-Testing-Schedule" itemprop="itemListElement">Availability/ ITSCM/ Security Testing Schedule</span></b>
</p>
<ul><li itemprop="description">A schedule for the <a href="/index.php/IT_Security_Management#ITIL_Security_Management_Testing" title="IT Security Management">regular testing</a> of all availability, continuity and security mechanisms, jointly maintained by <a href="/index.php/Availability_Management" title="Availability Management">Availability</a>, <a href="/index.php/IT_Service_Continuity_Management" title="IT Service Continuity Management">IT Service Continuity</a> and <strong class="selflink">Information Security Management</strong>.
</li></ul>
<p><b><span id="ITIL_Security_Management_Rules" itemprop="itemListElement">Event Filtering and Correlation Rules</span></b>
</p>
<ul><li itemprop="description">Rules and criteria used to determine if an Event is significant and to decide upon an appropriate response. Event Filtering and Correlation Rules are typically used by Event Monitoring systems. Some of those rules are defined during the Service Design stage, for example to ensure that Events are triggered when the required service availability is endangered.
</li><li><i>Note: The output "Event Filtering and Correlation Rules" has been added in ITIL 2011, to emphasize that (some) Event filtering and correlation rules should be designed by Information Security Management to support the detection of security issues.</i>
</li></ul>
<p><b><span id="ITIL_Security_Policy" itemprop="itemListElement">Information Security Policy</span></b>
</p>
<ul><li itemprop="description">The Information Security Management Policy describes and communicates the organization's approach to managing information security. It includes references to more specific <a href="/index.php/IT_Security_Management#Underpinning-Information-Security-Policy" title="IT Security Management">Underpinning Information Security Policies</a> which, for example, set binding rules for the use of systems and information.
</li></ul>
<p><b><span id="ITIL_Security_Report" itemprop="itemListElement">Information Security Report</span></b>
</p>
<ul><li itemprop="description">The Information Security Report provides other Service Management processes and IT Management with information related to Information Security issues.
</li></ul>
<p><b><span id="Security-Advisories" itemprop="itemListElement">Security Advisories</span></b>
</p>
<ul><li itemprop="description">A list of known security vulnerabilities compiled from input by third-party product suppliers. The list contains instructions for preventive measures and for the handling of security breaches once they occur.
</li></ul>
<p><b><span id="Security_Alert" itemprop="itemListElement">Security Alert</span></b>
</p>
<ul><li itemprop="description">A warning produced by Information Security Management, typically released when outbreaks of security threats are foreseeable or already under way. The aim is to make sure that users and IT staff are able to identify any attacks and take appropriate precautions.
</li></ul>
<p><b><span id="Security-Management-Information-System" itemprop="itemListElement">Security Management Information System (SMIS)</span></b>
</p>
<ul><li itemprop="description">A virtual repository of all Information Security Management data, usually stored in multiple physical locations.
</li></ul>
<p><b><span id="Test_Report" itemprop="itemListElement">Test Report</span></b>
</p>
<ul><li itemprop="description">A Test Report provides a summary of testing and assessment activities. A Test Report is created for example during Release tests in the Service Transition stage or during tests carried out by <a href="/index.php/Availability_Management" title="Availability Management">Availability</a>, <a href="/index.php/IT_Service_Continuity_Management" title="IT Service Continuity Management">IT Service Continuity</a> or <strong class="selflink">Information Security Management</strong>.
</li></ul>
<p><b><span id="Underpinning-Information-Security-Policy" itemprop="itemListElement">Underpinning Information Security Policy</span></b>
</p>
<ul><li itemprop="description">Underpinning Information Security Policies are specific policies complementing the <a href="/index.php/IT_Security_Management#ITIL_Security_Policy" title="IT Security Management">main Information Security Policy</a> by setting binding rules for the use of systems and information as well as for the use and delivery of services, with the aim of improving information security.
</li></ul>
</div><!-- end of schema.org/ItemList --><p></html>


;<span id="ITIL Security Report">Information Security Report</span>
==KPIs==
:The Information Security Report provides other Service Management processes and IT Management with information related to Information Security issues.


;<span id="Security-Advisories">Security Advisories</span>
<html><ul><li><a href="https://wiki.en.it-processmaps.com/index.php/ITIL_KPIs_Service_Design#ITIL_KPIs_Information_Security_Management" title="ITIL KPIs Security Management">Key Performance Indicators (KPIs) Information Security Management</a></li></ul>
:A list of known security vulnerabilities compiled from input by third-party product suppliers. The list contains instructions for preventive measures and for the handling of security breaches once they occur.
<p></html>


;<span id="ITIL Security Management Alert">Security Alert</span>
==Roles | Responsibilities==
:A warning produced by Information Security Management, typically released when outbreaks of security threats are foreseeable or already under way. The aim is to make sure that users and IT staff are able to identify any attacks and take appropriate precautions.


;<span id="Security-Management-Information-System">Security Management Information System (SMIS)</span>
'''<span id="Information Security Manager">Information Security Manager - Process Owner</span>
:A virtual repository of all Information Security Management data, usually stored in multiple physical locations.
*The Information Security Manager is responsible for ensuring the confidentiality, integrity and availability of an organization’s assets, information, data and IT services. He is usually involved in an organizational approach to Security Management which has a wider scope than the IT service provider, and includes handling of paper, building access, phone calls etc., for the entire organization.
 
;<span id="Test Report">Test Report</span>
:A Test Report provides a summary of testing and assessment activities. A Test Report is created for example during Release tests in the Service Transition stage or during tests carried out by [[Availability Management|Availability]], [[IT Service Continuity Management|IT Service Continuity]] or [[IT Security Management|Information Security Management]].
 
;<span id="Underpinning-Information-Security-Policy">Underpinning Information Security Policy</span>
:Underpinning Information Security Policies are specific policies complementing the [[IT Security Management#ITIL Security Policy|main Information Security Policy]] by setting binding rules for the use of systems and information as well as for the use and delivery of services, with the aim of improving information security.


<p>&nbsp;</p>
<p>&nbsp;</p>


== KPIs ==
{| class="wikitable" style="background: white;"
* [[ITIL KPIs Service Design#ITIL KPIs Information Security Management|KPIs Information Security Management]]
 
<p>&nbsp;</p>
 
== Roles | Responsibilities  ==
 
;<span id="Information Security Manager">Information Security Manager - Process Owner</span>
:The Information Security Manager is responsible for ensuring the confidentiality, integrity and availability of an organization’s assets, information, data and IT services. He is usually involved in an organizational approach to Security Management which has a wider scope than the IT service provider, and includes handling of paper, building access, phone calls etc., for the entire organization.
 
<p>&nbsp;</p>
 
{| border="1" cellpadding="5" cellspacing="0" style="text-align:center;" valign="top"
|-
|-
| valign="top"  colspan="7" style="background:#ffffdd;" align="center"| '''Responsibility Matrix: ITIL Security Management'''
|+ style="background:#013b5e; color:#ffffff; font-size: 120%" colspan="7"|'''Responsibility Matrix: ITIL Security Management'''
|-
|-
! width="50%" align="center" style="background:#ffffee;" | ITIL Role | Sub-Process
!style="background:#ffffee; width: 50%; text-align:center" | ITIL Role / Sub-Process
! style="background:#ffffee;" | [[IT Security Management#Information Security Manager|Information Security Manager]]
! style="background:#eeeeee;" | [[IT Security Management#Information Security Manager|Information Security Manager]]
! style="background:#ffffee;" | Service Owner[[#ITIL Security Roles|<small>[3]</small>]]
! style="background:#eeeeee;" | Service Owner[[#ITIL Security Roles|<small>[3]</small>]]
! style="background:#ffffee;" | Applications Analyst[[#ITIL Security Roles|<small>[3]</small>]]
! style="background:#eeeeee;" | Applications Analyst[[#ITIL Security Roles|<small>[3]</small>]]
! style="background:#ffffee;" | Technical Analyst[[#ITIL Security Roles|<small>[3]</small>]]
! style="background:#eeeeee;" | Technical Analyst[[#ITIL Security Roles|<small>[3]</small>]]
! style="background:#ffffee;" | IT Operator[[#ITIL Security Roles|<small>[3]</small>]]
! style="background:#eeeeee;" | IT Operator[[#ITIL Security Roles|<small>[3]</small>]]
! style="background:#ffffee;" | Facilities Manager[[#ITIL Security Roles|<small>[3]</small>]]
! style="background:#eeeeee;" | Facilities Manager[[#ITIL Security Roles|<small>[3]</small>]]
|-
|-
| align="left" |[[#ITIL Security Management Controls|Design of Security Controls]]
|style="text-align:left;" |[[#ITIL Security Management Controls|Design of Security Controls]]
| A[[IT Security Management#Accountable|<small>[1]</small>]]R[[IT Security Management#Responsible|<small>[2]</small>]]
| A[[IT Security Management#Accountable|<small>[1]</small>]]R[[IT Security Management#Responsible|<small>[2]</small>]]
| R
| R
Line 119: Line 145:
| -
| -
|-
|-
| align="left" |[[#ITIL Security Management Testing|Security Testing]]
|style="text-align:left;" |[[#ITIL Security Management Testing|Security Testing]]
| AR
| AR
| -
| -
Line 127: Line 153:
| R
| R
|-
|-
| align="left" |[[#ITIL Security Management Incidents|Management of Security Incidents]]
|style="text-align:left;" |[[#ITIL Security Management Incidents|Management of Security Incidents]]
| AR
| AR
| -
| -
Line 135: Line 161:
| -
| -
|-
|-
| align="left" |[[#ITIL Security Management Review|Security Review]]
|style="text-align:left;" |[[#ITIL Security Management Review|Security Review]]
| AR
| AR
| -
| -
Line 144: Line 170:
|-
|-
|}
|}
<p>&nbsp;</p>


'''Remarks'''
'''Remarks'''
Line 153: Line 177:
<span id="Responsible">[2] ''R: Responsible'' according to the RACI Model: Those who do the work to achieve a task within ITIL Security Management.</span>
<span id="Responsible">[2] ''R: Responsible'' according to the RACI Model: Those who do the work to achieve a task within ITIL Security Management.</span>


<span id="ITIL Security Roles">[3] siehe [[Roles within ITIL V3|&#8594; Role descriptions ...]]</span>
<span id="ITIL Security Roles">[3] siehe [[ITIL Roles|&#8594; Role descriptions ...]]</span>
 
==Notes==
 
<html>By:&#160;&#160;Stefan Kempter&#160;<a rel="author" href="https://www.linkedin.com/in/stefankempter"><img style="margin:0px 0px 0px 0px;" src="/images/bookmarking/linkedin.png" width="16" height="16" title="By: Stefan Kempter | Profile on LinkedIn" alt="Author: Stefan Kempter, IT Process Maps GbR" /></a>, IT Process Maps.</p>


<p>&nbsp;</p>
<p>&nbsp;</p>
<p><small>
<span itemprop="breadcrumb" itemscope itemtype="http://schema.org/BreadcrumbList">
<span itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem">
<a itemprop="item" href="https://wiki.en.it-processmaps.com/index.php/IT_Security_Management#Process_Description">
<span itemprop="name">Process Description</span></a>
<meta itemprop="position" content="1"></span> ›
<span itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem">
<a itemprop="item" href="https://wiki.en.it-processmaps.com/index.php/IT_Security_Management#Sub-Processes">
<span itemprop="name">Sub-Processes</span></a>
<meta itemprop="position" content="2"></span> ›
<span itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem">
<a itemprop="item" href="https://wiki.en.it-processmaps.com/index.php/IT_Security_Management#Definitions">
<span itemprop="name">Definitions</span></a>
<meta itemprop="position" content="3"></span> ›
<span itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem">
<a itemprop="item" href="https://wiki.en.it-processmaps.com/index.php/IT_Security_Management#Roles_.7C_Responsibilities">
<span itemprop="name">Roles</span></a>
<meta itemprop="position" content="4" /></span>
</span>
</small></p>
<!-- define schema.org/WebPage --> <span itemscope itemtype="https://schema.org/WebPage" itemref="md-webpage-description">
  <meta itemprop="name" content="Information Security Management" />
  <meta itemprop="alternativeHeadline" content="ITIL Security Management" />
  <meta itemprop="significantLinks" content="https://wiki.en.it-processmaps.com/index.php/ITIL_KPIs_Service_Design#ITIL_KPIs_Information_Security_Management" />
  <link itemprop="url" href="https://wiki.en.it-processmaps.com/index.php/IT_Security_Management" />
  <meta itemprop="inLanguage" content="en" />
  <link itemprop="citation" href="https://wiki.de.it-processmaps.com/index.php/IT_Security_Management" />
  <link itemprop="citation" href="https://wiki.es.it-processmaps.com/index.php/ITIL_Gestion_de_la_Seguridad_de_TI" />
  <meta itemprop="Headline" content="Information Security Management" />
  <link itemprop="isPartOf" href="https://wiki.en.it-processmaps.com/index.php/ITIL_Service_Design" />
  <link itemprop="primaryImageOfPage" href="https://wiki.en.it-processmaps.com/images/e/e7/Itil-security-management.jpg" />
  <span id="https://wiki.en.it-processmaps.com/images/e/e7/Itil-security-management.jpg" itemprop="image" itemscope itemtype="https://schema.org/ImageObject">
  <meta itemprop="caption" content="Information Security Management">
  <meta itemprop="contentUrl" content="https://wiki.en.it-processmaps.com/images/e/e7/Itil-security-management.jpg" />
  <meta itemprop="width" content="1200" />
  <meta itemprop="height" content="1200" />
  <meta itemprop="representativeOfPage" content="true"/>
  <meta itemprop="dateCreated" content="2011-09-19" />
  <meta itemprop="dateModified" content="2020-06-20" />
  <span itemprop="thumbnail" itemscope itemtype="https://schema.org/ImageObject">
    <meta itemprop="url" content="https://wiki.en.it-processmaps.com/images/thumb/e/e7/Itil-security-management.jpg/600px-Itil-security-management.jpg" />
    <meta itemprop="width" content="600" />
    <meta itemprop="height" content="600" />
  </span>
  <meta itemprop="keywords" content="Information Security Management" />
  <meta itemprop="keywords" content="ITIL Security Management" />
  </span>
  <link itemprop="author" href="https://www.linkedin.com/in/stefankempter" />
  <meta itemprop="author" content="Stefan Kempter" />
  <meta itemprop="creator copyrightHolder publisher" content="IT Process Maps" />
</span><p></html>


<!-- This page is assigned to the following categories: -->
<!-- This page is assigned to the following categories: -->
[[Category:ITIL V3]][[Category:ITIL 2011]][[Category:ITIL process]][[Category:Service Design|Information Security Management]][[Category:Information Security Management|!]]
[[Category:ITIL 4]][[Category:ITIL 2011]][[Category:ITIL V3]][[Category:ITIL practice]][[Category:ITIL process]][[Category:Service Design|Information Security Management]][[Category:Information Security Management|!]]
<!-- --- -->
<!-- --- -->

Latest revision as of 11:53, 31 December 2023

DE - ES - Information Security Managementdiese Seite auf Deutschesta página en español
DE - ES - Information Security Management


Objective: Information Security Management aims to ensure the confidentiality, integrity and availability of an organization's information, data and IT services. ITIL Security Management usually forms part of an organizational approach to security management which has a wider scope than the IT Service Provider.

Part of: Service Design

Process Owner: Information Security Manager

 

Process Description

ITIL V3 treats Information Security Management as part of the Service Design core volume, resulting in a better integration of this process into the Service Lifecycle (the previous ITIL version provided guidance on Security Management in a separate book).

Information Security Management ITIL
ITIL Security Management

The process has been updated to account for new information security concerns.

ITIL does not provide a detailed explanation of all aspects of Information Security Management, as there are dedicated and more detailed standards available (see, for example, ISO 27001). Rather, ITIL highlights the most important activities and assists in identifying interfaces with other Service Management processes.

Following the introduction of Design Coordination in ITIL 2011 the information flows have been adapted. The process overview of ITIL Security Management (.JPG) shows the key information flows (see fig. 1).

ITIL 4 refers to 'Information Security Management' as a general management practice.

 

Sub-Processes

These are the Information Management sub-processes and their process objectives:

Design of Security Controls

  • Process Objective: To design appropriate technical and organizational measures in order to ensure the confidentiality, integrity, security and availability of an organization's assets, information, data and services.

Security Testing

  • Process Objective: To make sure that all security mechanisms are subject to regular testing.

Management of Security Incidents

  • Process Objective: To detect and fight attacks and intrusions, and to minimize the damage incurred by security breaches.

Security Review

  • Process Objective: To review if security measures and procedures are still in line with risk perceptions from the business side, and to verify if those measures and procedures are regularly maintained and tested.

Definitions

The following ITIL terms and acronyms (information objects) are used in the Security Management process to represent process outputs and inputs:

Availability/ ITSCM/ Security Testing Schedule

Event Filtering and Correlation Rules

  • Rules and criteria used to determine if an Event is significant and to decide upon an appropriate response. Event Filtering and Correlation Rules are typically used by Event Monitoring systems. Some of those rules are defined during the Service Design stage, for example to ensure that Events are triggered when the required service availability is endangered.
  • Note: The output "Event Filtering and Correlation Rules" has been added in ITIL 2011, to emphasize that (some) Event filtering and correlation rules should be designed by Information Security Management to support the detection of security issues.

Information Security Policy

  • The Information Security Management Policy describes and communicates the organization's approach to managing information security. It includes references to more specific Underpinning Information Security Policies which, for example, set binding rules for the use of systems and information.

Information Security Report

  • The Information Security Report provides other Service Management processes and IT Management with information related to Information Security issues.

Security Advisories

  • A list of known security vulnerabilities compiled from input by third-party product suppliers. The list contains instructions for preventive measures and for the handling of security breaches once they occur.

Security Alert

  • A warning produced by Information Security Management, typically released when outbreaks of security threats are foreseeable or already under way. The aim is to make sure that users and IT staff are able to identify any attacks and take appropriate precautions.

Security Management Information System (SMIS)

  • A virtual repository of all Information Security Management data, usually stored in multiple physical locations.

Test Report

  • A Test Report provides a summary of testing and assessment activities. A Test Report is created for example during Release tests in the Service Transition stage or during tests carried out by Availability, IT Service Continuity or Information Security Management.

Underpinning Information Security Policy

  • Underpinning Information Security Policies are specific policies complementing the main Information Security Policy by setting binding rules for the use of systems and information as well as for the use and delivery of services, with the aim of improving information security.

KPIs

Roles | Responsibilities

Information Security Manager - Process Owner

  • The Information Security Manager is responsible for ensuring the confidentiality, integrity and availability of an organization’s assets, information, data and IT services. He is usually involved in an organizational approach to Security Management which has a wider scope than the IT service provider, and includes handling of paper, building access, phone calls etc., for the entire organization.

 

Responsibility Matrix: ITIL Security Management
ITIL Role / Sub-Process Information Security Manager Service Owner[3] Applications Analyst[3] Technical Analyst[3] IT Operator[3] Facilities Manager[3]
Design of Security Controls A[1]R[2] R R R - -
Security Testing AR - - - R R
Management of Security Incidents AR - - - - -
Security Review AR - - - - -

Remarks

[1] A: Accountable according to the RACI Model: Those who are ultimately accountable for the correct and thorough completion of the Information Security Management process.

[2] R: Responsible according to the RACI Model: Those who do the work to achieve a task within ITIL Security Management.

[3] siehe → Role descriptions ...

Notes

By:  Stefan Kempter , IT Process Maps.

 

Process Description  › Sub-Processes  › Definitions  › Roles