Preparing your Exciting Information Security Plan

Proper Scope of Information Security Plan

In our last post, we discussed the general goals of an Information Security Management System (ISMS) and some available standards and frameworks for such a system.

In this post, we will go over the basics of determining the proper scope of your organization’s ISMS, the importance of identifying the scope and tailoring it to the business, and Data Privacy and Classification.

What is the scope?

Simply put, the scope of the document is the parts of the organization that the policy will apply to. While for many small businesses, the scope will simply include “everything”, some businesses may have different branches or areas which consider an ISMS crucial, where it may not be quite as important for other areas.

Knowing which areas, you want to have in scope is helpful in ensuring that the information security plan does not become so large as to become impossible to properly implement and service. However, restricting the scope too tightly may result in overlooking areas that may become a risk down the road. The information security team and management should decide early on if any parts of the business are not to be considered in scope.

 
Things Commonly Considered within  Information Security Plan Scope

Due to the organization’s scope being tailored to business needs, we cannot provide an exhaustive list of things to consider; however, these are things that would commonly be considered within the scope:

  • Any physical offices or buildings that have restricted access
  • Networking, computing, storage, and backup systems
  • Operational data, policies, procedures, trade secrets, copyrights, patents, software developed in-house, and similar information
  • Employees, contractors, and business owners
  • Any data or information residing within third-party, vendor, or cloud systems
Data Privacy and Classification

All organizations generate large amounts of data; it is often helpful for scoping and policy-making to ensure that all this data is given a classification, owner, and labeled properly. Data classification is simply determining the level of secrecy any data your organization uses may have.

For example, some data may be derived from public sources or released to your customers and clients; given that this data is used outside of your organization, you are likely to be unconcerned with people having access to it.

However, you almost assuredly have internal data that you would very much not want those same people to be able to access; similarly, you may have internal data that all your employees may need to access for some reason or another, but also have data (for example, payroll databases and information) that should only be accessed by personnel who truly need access to that data. A solid data classification scheme makes it easier for you to ensure the proper users have proper access to the data they need.

Data ownership simply means that a particular category or form of data that your organization stores have a person that is ultimately responsible for ensuring that data is being properly classified and your organization’s ISMS policies are being properly applied to that piece of data. If something were to happen to that data, that person would ultimately be the one held responsible.

Our next post will detail the process behind performing a risk assessment of your organization.

Browse all insights