Information Assurance: Managing Organizational IT Security Risks

Understand IA concerns during each phase of the system life cycle
Understand system certification and accreditation (C&A)
We often hear the phrase "cradle to grave" used when speaking of the extent to which security affects each phase of the system life cycle. As true as this is, it does not go far enough. What we are dealing with is really a "conception to grave" responsibility. Security should be included in the inception and planning of the system; integrated into the system's design; only implemented with required security features installed; always operated with security features despite changes to configuration; and, at the end of its life cycle, disposed of in accordance with established procedures. Security is involved in each stage of the system's life cycle.
Security is not an end in itself; therefore, the operational requirements that drive the initial idea for the system may not be security related. Nevertheless, an assessment at this stage is necessary to determine the feasibility of the concept. For example, there is no point in expending time and money designing a system to perform a function prohibited by laws or regulations. Considerations include:
Sensitivity of the information (e.g., degree of required confidentiality, integrity, availability, and accountability)
Threats to the system or information
Location of the system (i.e., environmental concerns)
Interdependencies (e.g., other systems, networks, or processes)
Legal or regulatory restrictions
Organizational policy, procedures, and precedents
| Note | The IA manager's job is not to find every... |