1
00:00:06,480 --> 00:00:08,730
- In this lesson 23.2,

2
00:00:08,730 --> 00:00:12,090
we're gonna laser focus in
on governance documents.

3
00:00:12,090 --> 00:00:15,270
The governance documents are
used to communicate direction,

4
00:00:15,270 --> 00:00:18,390
expectation, and rules.

5
00:00:18,390 --> 00:00:20,790
The governance documents
are going to be derived

6
00:00:20,790 --> 00:00:23,250
from the information security strategy.

7
00:00:23,250 --> 00:00:25,050
And where does the strategy come from?

8
00:00:25,050 --> 00:00:28,380
The strategy is derived from
the desired or future state.

9
00:00:28,380 --> 00:00:29,940
So we determine our future state.

10
00:00:29,940 --> 00:00:31,451
From there, we get our strategy.

11
00:00:31,451 --> 00:00:34,770
And then from there, we develop
our governance documents.

12
00:00:34,770 --> 00:00:37,380
And that will ensure that
our governance documents

13
00:00:37,380 --> 00:00:39,120
are strategically aligned

14
00:00:39,120 --> 00:00:42,423
with the objectives and
goals of the organization.

15
00:00:44,460 --> 00:00:46,170
So let's look at governance communication.

16
00:00:46,170 --> 00:00:47,610
I wanna show you the sort of the pantheon

17
00:00:47,610 --> 00:00:50,850
of all of our different
types of communication.

18
00:00:50,850 --> 00:00:52,260
We have policies.

19
00:00:52,260 --> 00:00:54,540
Policies are supported by standards.

20
00:00:54,540 --> 00:00:57,030
Standards are supported by procedures.

21
00:00:57,030 --> 00:00:59,100
There are different types of procedures.

22
00:00:59,100 --> 00:01:03,063
We have simple step, hierarchical,
graphic, and flowchart.

23
00:01:04,140 --> 00:01:07,560
Standards are also
supported by guidelines.

24
00:01:07,560 --> 00:01:10,590
And policies are also
supported by agreements.

25
00:01:10,590 --> 00:01:13,200
So we're gonna be talking
about policy, standards,

26
00:01:13,200 --> 00:01:16,563
procedures, guidelines, and agreements.

27
00:01:17,970 --> 00:01:20,820
Now the objective of a
policy, really any policy,

28
00:01:20,820 --> 00:01:24,150
is to communicate and codify
management's requirements,

29
00:01:24,150 --> 00:01:25,920
and to provide direction.

30
00:01:25,920 --> 00:01:27,360
How we need to act?

31
00:01:27,360 --> 00:01:29,460
What we need to do?

32
00:01:29,460 --> 00:01:31,620
Now information security policies

33
00:01:31,620 --> 00:01:33,787
codify high-level requirements,

34
00:01:33,787 --> 00:01:35,610
and I can't stress that enough.

35
00:01:35,610 --> 00:01:37,650
High-level requirements

36
00:01:37,650 --> 00:01:40,500
for protecting information
and information assets

37
00:01:40,500 --> 00:01:44,070
and assuring are fundamental
principles of confidentiality,

38
00:01:44,070 --> 00:01:47,160
integrity, and availability.

39
00:01:47,160 --> 00:01:50,490
Now policies should be
approved and authorized

40
00:01:50,490 --> 00:01:53,280
by the organization's
highest governing body.

41
00:01:53,280 --> 00:01:54,540
So that might be a board of directors,

42
00:01:54,540 --> 00:01:56,040
your board of trustees, right?

43
00:01:56,040 --> 00:01:58,020
It might be agency leadership.

44
00:01:58,020 --> 00:02:02,302
It might be up the chain
of military command.

45
00:02:02,302 --> 00:02:06,060
In a small business, it may
be literally the owners.

46
00:02:06,060 --> 00:02:07,590
But they should be approved and authorized

47
00:02:07,590 --> 00:02:10,653
by the highest governing
body in your organization.

48
00:02:12,510 --> 00:02:14,400
Now well-developed policies

49
00:02:14,400 --> 00:02:16,830
generally remain relatively static

50
00:02:16,830 --> 00:02:18,657
over extended periods of time.

51
00:02:18,657 --> 00:02:21,450
You wanna reauthorize them annually,

52
00:02:21,450 --> 00:02:25,830
but most part modifications
should be pretty minor.

53
00:02:25,830 --> 00:02:30,030
And then we use agreements
to legally enforce policies

54
00:02:30,030 --> 00:02:33,030
and related governance publications.

55
00:02:33,030 --> 00:02:33,900
But I wanna go back

56
00:02:33,900 --> 00:02:38,820
and really stress that policies
are high-level documents

57
00:02:38,820 --> 00:02:41,670
that all those implementation details

58
00:02:41,670 --> 00:02:43,331
do not belong in a policy.

59
00:02:43,331 --> 00:02:45,690
We're gonna see that those
belong in a standard.

60
00:02:45,690 --> 00:02:48,150
And because the implementation details

61
00:02:48,150 --> 00:02:49,590
are not in the policy,

62
00:02:49,590 --> 00:02:50,850
that means that policy

63
00:02:50,850 --> 00:02:53,763
can remain relatively static over time.

64
00:02:55,650 --> 00:02:58,440
So let's do a survey of
different types of policies

65
00:02:58,440 --> 00:03:00,480
that you may be interacting with.

66
00:03:00,480 --> 00:03:02,310
We have our information security policy.

67
00:03:02,310 --> 00:03:03,900
Now our information security policy

68
00:03:03,900 --> 00:03:06,390
will have a lot of
different sections, right?

69
00:03:06,390 --> 00:03:09,124
It might have information about,

70
00:03:09,124 --> 00:03:12,390
you know, risk management
and access control

71
00:03:12,390 --> 00:03:16,830
and authentication and remote access.

72
00:03:16,830 --> 00:03:20,220
And you know, physical
security for, you know,

73
00:03:20,220 --> 00:03:22,290
our data centers and our wiring rooms,

74
00:03:22,290 --> 00:03:24,960
might have a section on
cloud, on training, right?

75
00:03:24,960 --> 00:03:27,330
Everything that has to do specifically

76
00:03:27,330 --> 00:03:29,387
with information security or cybersecurity

77
00:03:29,387 --> 00:03:33,300
would be in our information
security policy.

78
00:03:33,300 --> 00:03:36,240
Our business continuity
policy is very complimentary

79
00:03:36,240 --> 00:03:37,740
to our information security policy

80
00:03:37,740 --> 00:03:39,840
and is how we are going
to continue to operate

81
00:03:39,840 --> 00:03:43,230
as an organization in adverse conditions.

82
00:03:43,230 --> 00:03:45,180
A very important policy,

83
00:03:45,180 --> 00:03:47,670
but it's not part of the
information security policy

84
00:03:47,670 --> 00:03:49,410
generally because, right?

85
00:03:49,410 --> 00:03:50,820
It's really applicable

86
00:03:50,820 --> 00:03:54,060
to every business unit in an organization.

87
00:03:54,060 --> 00:03:56,370
The same thing of our disaster
recovery policy, right?

88
00:03:56,370 --> 00:03:58,980
That's gonna be high-level
governance document, right?

89
00:03:58,980 --> 00:04:01,740
About how we would
recover from a disaster.

90
00:04:01,740 --> 00:04:04,167
And then we have our incident
response policy, right?

91
00:04:04,167 --> 00:04:07,290
And we talked about this one
a little while ago, right?

92
00:04:07,290 --> 00:04:08,520
About all the components

93
00:04:08,520 --> 00:04:12,240
we need to have to have in
an incident response plan.

94
00:04:12,240 --> 00:04:15,120
And then of course, all
of those are referred to

95
00:04:15,120 --> 00:04:18,660
or just that we need to have
them actually in the policy.

96
00:04:18,660 --> 00:04:20,760
We have a software
development lifecycle policy

97
00:04:20,760 --> 00:04:22,470
that our developers or coders will use

98
00:04:22,470 --> 00:04:26,670
if we're developing any
software in our organization.

99
00:04:26,670 --> 00:04:29,910
We may have a configuration
and change management policy

100
00:04:29,910 --> 00:04:33,180
that may in fact be part of an
information security policy.

101
00:04:33,180 --> 00:04:35,760
It may be part of an IT policy.

102
00:04:35,760 --> 00:04:38,940
Very often, it's actually
going to be its own policy

103
00:04:38,940 --> 00:04:41,673
because it is applicable
across so many areas.

104
00:04:42,720 --> 00:04:43,950
A risk management policy,

105
00:04:43,950 --> 00:04:46,440
but how we are going to manage risk.

106
00:04:46,440 --> 00:04:47,940
Now part of a risk management policy.

107
00:04:47,940 --> 00:04:49,410
There may be references to risk

108
00:04:49,410 --> 00:04:51,330
in our information security policy.

109
00:04:51,330 --> 00:04:53,040
But again, a risk management policy

110
00:04:53,040 --> 00:04:54,750
tends to be enterprise risk,

111
00:04:54,750 --> 00:04:57,000
not just information security risk.

112
00:04:57,000 --> 00:05:00,270
And then an acceptable use
policy known as an AUP,

113
00:05:00,270 --> 00:05:02,907
which is an end-user-oriented policy.

114
00:05:02,907 --> 00:05:05,850
And it's a policy that we create

115
00:05:05,850 --> 00:05:08,370
to really help our users understand

116
00:05:08,370 --> 00:05:09,870
how they are supposed to behave.

117
00:05:09,870 --> 00:05:12,320
And we'll dive a little
bit deeper into that one.

118
00:05:15,060 --> 00:05:16,770
So I said that our policies

119
00:05:16,770 --> 00:05:19,260
were really, really high-level documents.

120
00:05:19,260 --> 00:05:22,410
So where do those
implementation details belong?

121
00:05:22,410 --> 00:05:24,072
Well, they belong in standards, right?

122
00:05:24,072 --> 00:05:27,210
Standards are the precise specification

123
00:05:27,210 --> 00:05:29,400
for the implementation of policy

124
00:05:29,400 --> 00:05:32,490
and dictate mandatory requirements.

125
00:05:32,490 --> 00:05:37,490
The standards absolutely,
absolutely must be unambiguous.

126
00:05:37,680 --> 00:05:39,270
When we group standards together,

127
00:05:39,270 --> 00:05:41,370
we refer to them as a baseline.

128
00:05:41,370 --> 00:05:43,410
Baselines are the aggregate of standards

129
00:05:43,410 --> 00:05:46,110
for a specific category or grouping,

130
00:05:46,110 --> 00:05:48,810
such as a platform or a device type

131
00:05:48,810 --> 00:05:50,883
or ownership or a location.

132
00:05:52,170 --> 00:05:54,450
And then optionally, we
might have guidelines.

133
00:05:54,450 --> 00:05:58,246
Guidelines help people understand
and conform to a standard.

134
00:05:58,246 --> 00:06:01,500
The guidelines should be
customized to the intended audience

135
00:06:01,500 --> 00:06:04,683
and are not mandatory, but
definitely very useful.

136
00:06:06,570 --> 00:06:08,310
So let's look at the relationship

137
00:06:08,310 --> 00:06:10,740
between a policy and a standard.

138
00:06:10,740 --> 00:06:12,150
I'm gonna give you an example.

139
00:06:12,150 --> 00:06:14,940
A policy might be
multifactor authentication

140
00:06:14,940 --> 00:06:16,710
is required for access to data

141
00:06:16,710 --> 00:06:19,140
and systems classified as confidential.

142
00:06:19,140 --> 00:06:20,550
That's a high-level statement.

143
00:06:20,550 --> 00:06:22,410
We're saying that for any data

144
00:06:22,410 --> 00:06:24,330
and system classified as confidential,

145
00:06:24,330 --> 00:06:26,670
we have to have
multifactor authentication.

146
00:06:26,670 --> 00:06:27,720
What we're not saying

147
00:06:27,720 --> 00:06:30,570
is the type of multifactor authentication

148
00:06:30,570 --> 00:06:31,403
we're going to have

149
00:06:31,403 --> 00:06:35,220
or any of the criteria
around those factors.

150
00:06:35,220 --> 00:06:39,900
That detail all belongs in your standard.

151
00:06:39,900 --> 00:06:42,375
So your standard might be
multifactor authentication

152
00:06:42,375 --> 00:06:46,080
required for data and systems
classified as confidential.

153
00:06:46,080 --> 00:06:48,730
Factor one will be an
eight-digit numeric pin.

154
00:06:48,730 --> 00:06:51,600
European characters changed every 90 days.

155
00:06:51,600 --> 00:06:54,510
A factor two will be a
biometric fingerprint.

156
00:06:54,510 --> 00:06:57,000
Those are the implementation details.

157
00:06:57,000 --> 00:06:58,920
And those are mandatory.

158
00:06:58,920 --> 00:07:03,920
So policy, high-level standard
implementation details.

159
00:07:03,960 --> 00:07:05,340
So we didn't even have to say

160
00:07:05,340 --> 00:07:07,560
what type of multifactor
it was in our policy.

161
00:07:07,560 --> 00:07:11,280
And that gives our
management a lot of latitude

162
00:07:11,280 --> 00:07:14,580
for how they're going
to apply that policy.

163
00:07:14,580 --> 00:07:15,630
And that means we don't have to go back

164
00:07:15,630 --> 00:07:16,890
and change the policy

165
00:07:16,890 --> 00:07:19,593
every time maybe there's
a change in technology.

166
00:07:20,850 --> 00:07:23,070
So policy, high-level standard

167
00:07:23,070 --> 00:07:26,103
is our implementation
details that are mandatory.

168
00:07:27,480 --> 00:07:31,050
Procedures are instructions
on how to carry out an action.

169
00:07:31,050 --> 00:07:34,920
Now procedures focus on very
discreet steps or actions

170
00:07:34,920 --> 00:07:38,313
with a specific starting
point and ending point.

171
00:07:39,600 --> 00:07:42,150
So we have four types of
procedures you wanna recognize.

172
00:07:42,150 --> 00:07:45,750
Simple step, hierarchical,
graphic, and flowchart.

173
00:07:45,750 --> 00:07:47,790
A simple step is just what it sounds like.

174
00:07:47,790 --> 00:07:49,680
It lists sequential actions.

175
00:07:49,680 --> 00:07:50,640
No decision making.

176
00:07:50,640 --> 00:07:53,610
Step one, step two, step
three, step four, step five.

177
00:07:53,610 --> 00:07:56,010
Hierarchal organizes the instructions

178
00:07:56,010 --> 00:07:58,444
in a hierarchal structure

179
00:07:58,444 --> 00:08:01,863
where each level is nested
within the one above it.

180
00:08:03,690 --> 00:08:07,590
Graphic presents in
pictorial or symbol form.

181
00:08:07,590 --> 00:08:10,440
We'll use a flowchart
to communicate a process

182
00:08:10,440 --> 00:08:12,990
or when decision making is required.

183
00:08:12,990 --> 00:08:15,180
So yes, no, stop, go, if then.

184
00:08:15,180 --> 00:08:16,893
That'll all happen in a flowchart.

185
00:08:18,690 --> 00:08:20,010
And then we have plans.

186
00:08:20,010 --> 00:08:22,050
Plan is a detailed strategy

187
00:08:22,050 --> 00:08:25,050
or tactic for doing or
achieving something.

188
00:08:25,050 --> 00:08:27,527
Now the function of a plan
is to provide instructions

189
00:08:27,527 --> 00:08:29,525
and guidance on how to execute

190
00:08:29,525 --> 00:08:33,690
or respond to a situation
within a certain timeframe,

191
00:08:33,690 --> 00:08:37,350
usually with defined stages
and with designated resources.

192
00:08:37,350 --> 00:08:40,110
So plans we would expect
to see in an organization

193
00:08:40,110 --> 00:08:42,840
would be things like our
disaster recovery plan,

194
00:08:42,840 --> 00:08:44,820
our business continuity plan,

195
00:08:44,820 --> 00:08:48,903
our incident response plan,
our communications plan.

196
00:08:51,750 --> 00:08:54,810
Now I mentioned when we were
doing our survey of policies,

197
00:08:54,810 --> 00:08:57,030
the acceptable use policy.

198
00:08:57,030 --> 00:08:58,530
I wish this had a different name

199
00:08:58,530 --> 00:09:00,060
because it's really the exception

200
00:09:00,060 --> 00:09:02,610
to everything I just
told you about policies.

201
00:09:02,610 --> 00:09:04,130
The acceptable use policy

202
00:09:04,130 --> 00:09:07,080
details your user community obligations

203
00:09:07,080 --> 00:09:09,990
pertaining to information
and information systems.

204
00:09:09,990 --> 00:09:12,110
So even though it has
the word policy in it,

205
00:09:12,110 --> 00:09:13,800
it has a lot of details.

206
00:09:13,800 --> 00:09:17,550
It really explains what
you can and can't do

207
00:09:17,550 --> 00:09:20,010
as well as some other information.

208
00:09:20,010 --> 00:09:21,210
But what I really wanna stress here

209
00:09:21,210 --> 00:09:23,310
is even though it says the word policy,

210
00:09:23,310 --> 00:09:26,520
it's going to have a lot
of implementation details

211
00:09:26,520 --> 00:09:30,213
or required or expected
actions and activities.

212
00:09:31,650 --> 00:09:34,696
So the AUP is gonna contain
rules that specifically pertain

213
00:09:34,696 --> 00:09:37,050
to acceptable behavior,

214
00:09:37,050 --> 00:09:38,670
the activities that are required

215
00:09:38,670 --> 00:09:40,740
and actions that are prohibited.

216
00:09:40,740 --> 00:09:42,870
But all we want in our AUP

217
00:09:42,870 --> 00:09:46,230
are things that really are
applicable to our user community.

218
00:09:46,230 --> 00:09:48,510
And I want you to think about the AUP

219
00:09:48,510 --> 00:09:50,070
as a teaching document.

220
00:09:50,070 --> 00:09:52,650
It's a teaching document
that develops awareness

221
00:09:52,650 --> 00:09:55,470
and teaches the importance
of information security

222
00:09:55,470 --> 00:09:57,600
or cybersecurity practices.

223
00:09:57,600 --> 00:10:00,090
Now the AUP should be
written in a language

224
00:10:00,090 --> 00:10:04,383
that can be easily and absolutely
unequivocally understood.

225
00:10:06,180 --> 00:10:08,910
So what are some of the
common elements of an AUP?

226
00:10:08,910 --> 00:10:10,740
Data protection, authentication,

227
00:10:10,740 --> 00:10:13,680
application, communication,
internet, mobile device,

228
00:10:13,680 --> 00:10:15,990
remote access and incident reporting.

229
00:10:15,990 --> 00:10:18,120
So data protection would really explain

230
00:10:18,120 --> 00:10:21,210
their data classifications
and the handling standards

231
00:10:21,210 --> 00:10:23,370
for the different classifications.

232
00:10:23,370 --> 00:10:24,690
Authentication would include things

233
00:10:24,690 --> 00:10:26,250
like our login requirements

234
00:10:26,250 --> 00:10:29,820
including password standards
and use of tokens or biometric.

235
00:10:29,820 --> 00:10:32,370
The applications would
be about procurement

236
00:10:32,370 --> 00:10:33,900
who can get an application, right?

237
00:10:33,900 --> 00:10:35,760
Installation and licensing.

238
00:10:35,760 --> 00:10:37,650
Communication would be about written

239
00:10:37,650 --> 00:10:40,380
and verbal communication
use and limitations.

240
00:10:40,380 --> 00:10:42,120
So what you can and can't say

241
00:10:42,120 --> 00:10:45,330
including in your personal
email or social media.

242
00:10:45,330 --> 00:10:47,640
The internet would be about internet use,

243
00:10:47,640 --> 00:10:49,890
activity, and engagement.

244
00:10:49,890 --> 00:10:52,469
Mobile device is the use,
configuration, activity,

245
00:10:52,469 --> 00:10:54,750
and device protection.

246
00:10:54,750 --> 00:10:57,180
Remote access, again use of remote access,

247
00:10:57,180 --> 00:10:58,988
configuration type of activity,

248
00:10:58,988 --> 00:11:00,810
and the physical security

249
00:11:00,810 --> 00:11:01,920
if you're doing remote access,

250
00:11:01,920 --> 00:11:03,960
let's say you have a home office.

251
00:11:03,960 --> 00:11:05,430
And then incident reporting.

252
00:11:05,430 --> 00:11:06,870
Instructions on how to spot

253
00:11:06,870 --> 00:11:09,330
and how to report suspicious activity.

254
00:11:09,330 --> 00:11:10,680
Now there may be more pieces

255
00:11:10,680 --> 00:11:12,960
than that in yours or
on ones that you see.

256
00:11:12,960 --> 00:11:16,263
But these are then the fairly
standard common elements.

257
00:11:17,400 --> 00:11:18,810
Now there may be two agreements

258
00:11:18,810 --> 00:11:22,080
that you are required to
sign before you have access

259
00:11:22,080 --> 00:11:23,971
to information or information systems.

260
00:11:23,971 --> 00:11:26,910
One is known as an NDA,
non-disclosure agreement

261
00:11:26,910 --> 00:11:28,830
also called a confidentiality agreement.

262
00:11:28,830 --> 00:11:30,300
And of course, the second one,

263
00:11:30,300 --> 00:11:32,760
which you will be required
almost everywhere,

264
00:11:32,760 --> 00:11:35,280
is the acceptable use agreement.

265
00:11:35,280 --> 00:11:37,140
An NDAA, non-disclosure agreement

266
00:11:37,140 --> 00:11:40,931
or confidentiality agreement
establishes data ownership

267
00:11:40,931 --> 00:11:44,820
and the reason that data is
being provided or being shared.

268
00:11:44,820 --> 00:11:47,250
It stipulates data use criteria.

269
00:11:47,250 --> 00:11:48,925
It protects data disclosure,

270
00:11:48,925 --> 00:11:51,323
'cause it says how
under what circumstances

271
00:11:51,323 --> 00:11:53,940
can this data be shared or disclosed?

272
00:11:53,940 --> 00:11:57,240
It does prevent forfeiture
of patent rights

273
00:11:57,240 --> 00:11:58,530
and it is survivable.

274
00:11:58,530 --> 00:12:00,240
It survives the relationship.

275
00:12:00,240 --> 00:12:02,790
So even though you may not
be an employee there anymore,

276
00:12:02,790 --> 00:12:05,280
if you have signed an NDA agreement,

277
00:12:05,280 --> 00:12:06,870
it will have a timeframe.

278
00:12:06,870 --> 00:12:10,233
So maybe for five years after
you've left the organization.

279
00:12:11,550 --> 00:12:13,320
Now the acceptable use agreement

280
00:12:13,320 --> 00:12:15,750
or the acceptable use policy agreement,

281
00:12:15,750 --> 00:12:19,290
the user acknowledges that they understand

282
00:12:19,290 --> 00:12:23,400
and that they agree to abide
by the acceptable use policy

283
00:12:23,400 --> 00:12:25,295
including any violation sanctions

284
00:12:25,295 --> 00:12:28,083
up to and including termination.

285
00:12:29,370 --> 00:12:31,740
Now that agreement that
they're signing, right?

286
00:12:31,740 --> 00:12:34,350
Should really clearly state

287
00:12:34,350 --> 00:12:36,750
if and how the user will be monitored

288
00:12:36,750 --> 00:12:38,370
and the limitations of privacy.

289
00:12:38,370 --> 00:12:41,490
So what their privacy
expectation should be?

290
00:12:41,490 --> 00:12:43,500
Now the agreement should be executed

291
00:12:43,500 --> 00:12:47,070
prior to being granted
access to any information

292
00:12:47,070 --> 00:12:48,780
or information systems.

293
00:12:48,780 --> 00:12:50,280
Which means during the orientation,

294
00:12:50,280 --> 00:12:52,710
we're gonna give someone
the acceptable use policy

295
00:12:52,710 --> 00:12:55,110
and the corresponding
acceptable use agreement

296
00:12:55,110 --> 00:12:57,090
and maybe the NDA agreement.

297
00:12:57,090 --> 00:12:57,990
During that orientation,

298
00:12:57,990 --> 00:12:59,100
we really want to go

299
00:12:59,100 --> 00:13:00,810
through that acceptable use policy with.

300
00:13:00,810 --> 00:13:02,760
Then we want them to understand, right?

301
00:13:02,760 --> 00:13:05,190
What the expectations are.

302
00:13:05,190 --> 00:13:07,350
And we really want them to make sure

303
00:13:07,350 --> 00:13:10,593
that they get it all before
they sign the agreement.

304
00:13:12,510 --> 00:13:15,240
And that my friends, brings us
to a three-second challenge.

305
00:13:15,240 --> 00:13:17,490
Five challenge questions,
three seconds each.

306
00:13:18,630 --> 00:13:21,240
Question one, high-level
governance document.

307
00:13:21,240 --> 00:13:22,683
One, two, three.

308
00:13:23,580 --> 00:13:24,830
That's gonna be a policy.

309
00:13:25,980 --> 00:13:28,920
Number two, mandatory
implementation requirement

310
00:13:28,920 --> 00:13:31,080
related to policies.

311
00:13:31,080 --> 00:13:32,910
One, two, three.

312
00:13:32,910 --> 00:13:34,890
It's gonna be our standards.

313
00:13:34,890 --> 00:13:39,300
Number three, specific instructions
for carrying out a task.

314
00:13:39,300 --> 00:13:40,803
One, two, three.

315
00:13:41,850 --> 00:13:43,250
That's gonna be a procedure.

316
00:13:44,220 --> 00:13:46,150
Number four, a detailed roadmap

317
00:13:46,150 --> 00:13:48,603
for doing or achieving something.

318
00:13:49,470 --> 00:13:50,853
One, two, three.

319
00:13:51,960 --> 00:13:53,700
That's a plan.

320
00:13:53,700 --> 00:13:55,555
And lastly, number five,

321
00:13:55,555 --> 00:13:57,480
an agreement that should be executed

322
00:13:57,480 --> 00:13:59,040
prior to being granted access

323
00:13:59,040 --> 00:14:01,710
to information or information systems.

324
00:14:01,710 --> 00:14:03,990
One, two, three.

325
00:14:03,990 --> 00:14:05,940
That's gonna be our
acceptable use agreement

326
00:14:05,940 --> 00:14:08,733
or acceptable use policy agreement.

327
00:14:10,980 --> 00:14:13,170
All right, let's do a security in action

328
00:14:13,170 --> 00:14:15,540
about developing a policy.

329
00:14:15,540 --> 00:14:17,940
During a routine software audit,

330
00:14:17,940 --> 00:14:21,180
numerous instances of
unlicensed operating systems

331
00:14:21,180 --> 00:14:23,280
and applications were identified.

332
00:14:23,280 --> 00:14:26,130
This violation appeared
to be unintentional

333
00:14:26,130 --> 00:14:30,270
and related to the proliferation
of virtual machines.

334
00:14:30,270 --> 00:14:33,210
Now in addition to fixing the issue ASAP,

335
00:14:33,210 --> 00:14:36,570
the audit report also
recommended developing a policy

336
00:14:36,570 --> 00:14:38,880
and supporting governance documents.

337
00:14:38,880 --> 00:14:40,830
And you've been assigned the task.

338
00:14:40,830 --> 00:14:42,900
So what's your plan of action?

339
00:14:42,900 --> 00:14:46,140
So just our review, we had
this routine software audit

340
00:14:46,140 --> 00:14:49,080
and we found that we
had numerous instances

341
00:14:49,080 --> 00:14:53,430
of unlicensed operating
systems and applications.

342
00:14:53,430 --> 00:14:54,840
We don't think it was intentional.

343
00:14:54,840 --> 00:14:56,160
It's just unintentional

344
00:14:56,160 --> 00:14:57,900
and probably 'cause we
just have a lot of VMs,

345
00:14:57,900 --> 00:15:00,210
a lot of virtual machines around.

346
00:15:00,210 --> 00:15:04,140
So you had to fix that,
the licensing issue ASAP.

347
00:15:04,140 --> 00:15:05,910
But the audit report said, you know what?

348
00:15:05,910 --> 00:15:07,260
We need a policy

349
00:15:07,260 --> 00:15:10,800
and supporting governance
documents about this.

350
00:15:10,800 --> 00:15:13,290
And you have been assigned this task.

351
00:15:13,290 --> 00:15:15,330
So what's your action plan?

352
00:15:15,330 --> 00:15:16,530
Go ahead and put me on pause.

353
00:15:16,530 --> 00:15:17,610
Think about that action plan

354
00:15:17,610 --> 00:15:19,560
then come back and we'll talk about it.

355
00:15:21,660 --> 00:15:22,493
Well, first of all,

356
00:15:22,493 --> 00:15:24,900
remember a policy is
a high-level document.

357
00:15:24,900 --> 00:15:28,800
We don't want a lot of
implementation details in our policy.

358
00:15:28,800 --> 00:15:30,660
So research, solicit input,

359
00:15:30,660 --> 00:15:33,090
and write a policy that
is strategically aligned

360
00:15:33,090 --> 00:15:35,940
with the organizational objectives,

361
00:15:35,940 --> 00:15:37,770
but very high level, right?

362
00:15:37,770 --> 00:15:39,780
And then be sure to gain consensus.

363
00:15:39,780 --> 00:15:43,140
Get people to agree and
buy in to this policy.

364
00:15:43,140 --> 00:15:45,450
Writing a policy that nobody
agrees with, nobody likes,

365
00:15:45,450 --> 00:15:48,201
and nobody wants to, you
know, abide by or enforce,

366
00:15:48,201 --> 00:15:49,530
well that's useless.

367
00:15:49,530 --> 00:15:51,090
So we've gotta gain consensus.

368
00:15:51,090 --> 00:15:53,040
And sometimes that means
there's multiple rewrites

369
00:15:53,040 --> 00:15:54,540
of a policy till we get there.

370
00:15:55,735 --> 00:15:58,800
Then you're going to submit
the policy for authorization.

371
00:15:58,800 --> 00:16:00,150
So you'll probably submit it first

372
00:16:00,150 --> 00:16:02,970
to maybe the steering committee.

373
00:16:02,970 --> 00:16:05,010
You'll get their, you know, blessing on it

374
00:16:05,010 --> 00:16:07,530
and then it will go up to
the board of directors.

375
00:16:07,530 --> 00:16:09,210
And then you're gonna wanna develop

376
00:16:09,210 --> 00:16:10,830
corresponding standards, right?

377
00:16:10,830 --> 00:16:12,090
Those are those, you know,

378
00:16:12,090 --> 00:16:15,450
precise mandatory implementation details

379
00:16:15,450 --> 00:16:17,473
if applicable guidelines, right?

380
00:16:17,473 --> 00:16:20,310
And if applicable procedures.

381
00:16:20,310 --> 00:16:21,840
And then you're going to wanna publish

382
00:16:21,840 --> 00:16:23,040
those documents, right?

383
00:16:23,040 --> 00:16:24,892
In a publicly accessible manner

384
00:16:24,892 --> 00:16:29,310
however you do your digital
library in your organization

385
00:16:29,310 --> 00:16:31,140
and you're gonna wanna provide training

386
00:16:31,140 --> 00:16:33,150
to the applicable user community.

387
00:16:33,150 --> 00:16:36,840
And if you think that this is
actually a user issue as well,

388
00:16:36,840 --> 00:16:39,060
you're probably gonna
wanna add it to the AUP,

389
00:16:39,060 --> 00:16:40,920
the acceptable use policy.

390
00:16:40,920 --> 00:16:42,900
Now more than likely, your users probably

391
00:16:42,900 --> 00:16:45,750
don't have the right to install
software, but maybe they do.

392
00:16:45,750 --> 00:16:49,710
And if they do, you'd wanna
add this to the AUP as well.

393
00:16:49,710 --> 00:16:52,233
Doing all that, security in action.

394
00:16:53,520 --> 00:16:54,930
There you go, your word cloud.

395
00:16:54,930 --> 00:16:57,930
I think the thing that people
struggle with most, right?

396
00:16:57,930 --> 00:17:00,420
Is the difference between
a policy and standard.

397
00:17:00,420 --> 00:17:02,460
So make sure that you
have a lot of clarity

398
00:17:02,460 --> 00:17:05,463
about what's different between
the policy and the standard.

399
00:17:06,840 --> 00:17:09,213
All right, when you're
ready, let's do a quiz.
