Mar 06 2014

Business Downtime and Disaster Recovery

Category: BCP,DRPDISC @ 10:53 pm

Infographic: Business Downtime and Disaster Recovery

The Internet is the largest store of information ever created, and those who can harness its power stand to reap tremendous rewards. However, handling data is also a significant responsibility, and disasters can cause severe problems. Here are a few facts about downtime and how to recover from disasters.
Infographic Disaster Recovery

Causes of Downtime

The most common cause of downtime is UPS battery failure, which is attributable to power failures. Many of these failures begin at the power plant, but some can be created by faulty wiring. Errors are a close second for causing downtime, and cyber attacks and equipment failure trail after them. Most causes of downtime are preventable through better security and better power management.

Effects of Downtime

Downtime has a clear effect on businesses that operate online. Customers cannot place orders when websites are down, and clients cannot rely on services hosted by offline servers. The long-term effects can be even more damaging. Customers may choose to make their purchases elsewhere, and clients may move to a different provider who promises better reliability.

How to Implement a Disaster Recovery Plan (DRP)

The most effective way to deal with disasters is to use servers provided by experts. One option is to purchase a hosted dedicated server that is rated to handle problems gracefully and effectively. Those who choose to host their own servers will want to ensure that data is kept safe through RAID arrays and periodic backups. It is important to ensure that backups are also stored in a remote location where they will not be destroyed by local disasters.

Businesses will also need to ensure that everyone knows what to do when disaster strikes. UPS batteries provide a limited amount of time to respond, but they are worthless if employees don’t know what to do. Automation can help, but there are certain tasks and decisions people will have to make.

Data is the lifeblood of online businesses, and high uptime ratings are essential for keeping customers and clients happy. However, many companies still fail to plan for disasters effectively, and many have been bitten by small mistakes that led to disastrous results. Fortunately, there are a number of options available for handling disasters effectively and preventing greater harm.

Why achieve a Disaster Recovery and Business Continuity plan


Feb 18 2014

Comprehensive Cyber Security Risk Management Toolkit

Category: cyber security,Security Risk AssessmentDISC @ 11:30 am

Cyber Security Toolkit

 

Govern and manage Cyber Security risk with this unique comprehensive toolkit suite

 

Comprehensive Cyber Security Risk Management Toolkit Suite – Use the Cyber Security Governance & Risk Management Toolkit for a new, fresh implementation of a comprehensive management system that will also be capable of ISO27001 certification, or take advantage of this toolkit’s modular

There are a number of standalone, best practice approaches to managing cyber risk, none of which is on its own completely satisfactory. This toolkit helps you make an enormous leap forward by consolidating five separate approaches into a single, comprehensive, robust framework.

• PAS 555:2013 is the new standard for cyber security risk governance and management; it was created to work with a range of other standards;
• ISO/IEC 27032 is the international guidance standard for managing cyber security risk;
• The Cloud Controls Matrix was developed by the Cloud Security Alliance for cloud service providers;
• Ten Steps to Cyber Security is the methodology developed by the UK’s Business Department to help organizations of all sizes secure their cyber defenses;
• ISO/IEC 27001: 2013 is the internationally recognized standard against which an information security management system can achieve accredited certification.

Use the Cyber Security Governance & Risk Management Toolkit for a new, fresh implementation of a comprehensive management system that will also be capable of ISO27001 certification, or take advantage of this toolkit’s modular construction and control mapping matrix to add its additional controls to an existing ISO27001 management system.

This Cyber Security Governance & Risk Management Toolkit recognizes that mobile device management is a critical component of effective cyber risk control and therefore includes the ITGP BYOD Policy Toolkit as a value-added extra.

Included in this comprehensive toolkit suite is:

Tags: Cloud Security Alliance, ISO/IEC 27001, National Institute of Standards and Technology, Risk management


Feb 13 2014

PRAGMATIC Security Metrics

Category: Security MetricsDISC @ 10:52 am

PRAGMATIC Security Metrics

Applying Metametrics to Information Security

 

Whereas other authors are strong on the number theory behind metrics and measurement, PRAGMATIC Security Metrics is a reader-friendly guide for hard-working security practitioners.  Without totally ignoring the underlying complexities, the book explains and interprets security metrics straightforwardly, adding a unique new ingredient to the mix: the PRAGMATIC method.

PRAGMATIC Security Metrics explains:

  • Why information security is vital, yet (as with risk management in general) so difficult to get right;
  • Why meaningful metrics are necessary to manage anything systematically and rationally, instead of relying purely on guesswork, experience and gut feel;
  • Who needs security metrics – who are the audiences, consumers and users of metrics;
  • How information security is currently measured – an overview of approaches suggested used and elsewhere;
  • Finding or developing potential (candidate) security metrics, including a few less conventional sources;
  • Assessing and scoring potential security metrics using the PRAGMATIC method;
  • 150+ example security metrics, structured in line with ISO27k, scored using the PRAGMATIC method, and discussed as if they were being actively considered by management;
  • Advanced security metrics – as if the rest of this isn’t hard enough already!;
  • Using security metrics – analysis, presentation, motivation …;
  • The downsides of metrics – possible drawbacks to having more effective security metrics;
  • A case study – a realistic worked example, developing a set of security metrics for Acme Enterprises Inc, an hypothetical commercial organization facing a range of strategic, managerial and operational challenges;
  • Conclusions including a set of take-home messages – things to put into practice immediately.

At face value, the PRAGMATIC method is just a way to score security metrics, but there’s much more to it than that.  Think about it: how does your organization determine which security metrics are worth using?  If you pick up a suggestion for a new metric from a book, a friend or a flash of inspiration, how do you assess its merits?  The usual approach is entirely informal and subjective.  Scoring and assessing the metric in a structured way forces you to think it through, in detail.

What about the recipients or audiences for your metrics: do you deliver the security metrics you feel are important, or do you make the effort to find out what they want – and if so, how do you frame that discussion?  What do you do to make them set aside the time to work out and explain their needs?

The PRAGMATIC method is straightforward, cheap and easy to apply, meaning that busy security managers can get up and running in a matter of hours.

Metrics are used not only to track and report performance but to identify problem areas and opportunities, and so drive security improvements.  With a focus on using measurement data in support of management decisions, the book takes the discussion up a level by elaborating on the design of an information security measurement system with obvious application in support of an information security management system as described by ISO/IEC 27001.

As soon as you appreciate the power of the PRAGMATIC method, you’ll be itching to put it into practice, especially if you, your colleagues and managers are presently struggling with security metrics.  Aside from the P.R.A.G.M.A.T.I.C. mnemonic representing nine criteria for assessing and scoring metrics, the approach is pragmatic in the ordinary everyday sense of the word.  You certainly don’t need a doctorate in statistics to make use of this book!  Practical tips are scattered liberally throughout, with further information and references in the footnotes.  We separated them out from the main text to encourage you to read quickly through the book at first to understand the overall approach, then go back to explore particular aspects in more detail as you apply the learning.  It is an introductory guide/overview and an implementation guide/training manual, all rolled into one.

by W. Krag Brotby and
Gary Hinson

ISBN: 978-1439881521 and 1439881529

Pages: 512 (150,000 words)

Publisher: Auerbach/CRC Press

Published: 2013

Order your copy today!


Feb 09 2014

Why to use hardware-encrypted USB sticks

Category: data securityDISC @ 10:17 pm

Hardware encryption has tangible benefits as file sharing and mobility tools, as backup drives and much more. Also hardware based encryption is more secure because the keys are embedded in the flash drive, require physical access to get, and very specialized knowledge to extract them.

  • Safeguard keys and critical security parameters within crypto-hardware
  • Authentication takes place on the hardware
  • Cost-effective in medium and larger application environments, easily scalable
  • Encryption is tied to a specific device, so encryption is “always on”
  • Does not require any type of driver installation or software installation on host PC
  • Protects against the most common attacks, such as cold boot attacks, malicious code, brute force attack

if you want your organization to avoid the risk of a data breach, you need to use hardware-encrypted USB sticks when you transfer data outside of the organisation, such as SafeXs 3.0. Using SafeXs 3.0 sticks will protect any data stored on them to a high degree as the data is hardware encrypted, which is more secure than using software encryption.

You should also use a USB stick management solution such as SafeConsole to ensure you are managing your secure USB sticks. This offers the advantage of being able to remote wipe data if a stick goes missing, enforce security policy across your sticks and a whole host of other security features.

Ensure your information security runs smooth through the use of a simple, secure USB stick such as SafeXs 3.0 that is  used in conjunction with SafeConsole Secure USB Management.

Integral® 16GB Crypto Drive – FIPS 197 Encrypted USB

Hardware Encrypted USB Flash Drive


Feb 07 2014

Why achieve a Disaster Recovery and Business Continuity plan

Category: BCP,DRPDISC @ 1:34 pm

What would you do if your systems were hacked or compromised by a virus? How would your IT systems cope in the event of flooding or an explosion?

What if your IT systems simply stopped working?

IT has brought many benefits to business. However, IT failures can seriously damage your ability to deliver products and services, harm your company’s reputation, and jeopardize your relationship with your customers. In short, poorly managed IT problems could threaten the survival of your business.

Create a Survival Plan

If you want to protect your business, you need to put in place a business continuity (BC) and disaster recovery (DR) plan to help your business survive. Disaster Recovery and Business Continuity, a quick guide for organizations and business managers shows you how to develop a plan that will:

•keep your information safe
•safeguard your company from viruses and phishing scams.
•store data safely, and prevent years of work from being lost by accident.
•ensure your communication links are secure, and keep you connected when disaster strikes
•bomb-proof your data
•protect your data in the event of fire or flood.

Read BCP/DRP practical guide and start building a business survival plan today


Jan 31 2014

How to Achieve Cyber Resilience

Category: cyber securityDISC @ 1:09 pm

Becoming cyber resilient will give your organization the best chance of defending itself against and surviving from cyber attacks.

What does ‘cyber resilience’ mean?

Cyber resilience is the ability to repel cyber attacks while protecting critical business assets, rapidly adapting and responding to business disruptions and maintain continuous business operations.

So how do I become Cyber Resilient?

IT Governance has developed a 7-step approach to achieving cyber resilience. See the graphic below and click to enlarge.

7steps

9781849285261_frontcoveronly_rgb_v1 Cyber Resilience Core Standards Kit 

These standards will help you to implement a management system that will allow you to take advantage of the opportunities associated with operating in cyberspace whilst mitigating the threats and risks.
Includes the information security standards ISO27001 and ISO27002 and the business continuity standards ISO22301 and ISO22313.

 

Build your knowledge of these key areas and be ready to help deliver your organizations cyber resilience strategy

Developing knowledge of the best practice advice and guidance in the key standards ISO27001 & ISO22301 is key to delivering a successful cyber resilience strategy. Whatever your preferred method of learning, IT Governance have the products to help build the knowledge and skills you need.

An Introduction to Information Security and ISO 27001 (2013) Written by acknowledged ISO27001 expert, Steve Watkins, this pocket guide introduces the principles of information security management and ISO27001. This guide will help you understand how to start planning a project to implement effective, reliable and auditable systems.
9781849285261_frontcoveronly_rgb_v1 ISO22301 – A Pocket GuideISO22301: A Pocket Guide will help you understand the Business Continuity international practice, and provides guidance on the best way to implement a fit-for-purpose BCMS.


Jan 21 2014

Why Two Thirds of Personal Banking Apps Have Vulnerabilities

Category: App Security,Mobile SecurityDISC @ 11:12 pm
Image representing iPhone as depicted in Crunc...

Image via CrunchBase

Personal Banking Apps study has been out,  a security researcher spent about 40 hours testing iPhone and iPad banking applications from the top 60 most influential banks in the world and his findings were totally shocking.

40 of those 60 applications were found to have major mobile security vulnerabilities, which is not something you’d expect to find in an application which authenticate you to your bank.

The conducted tests were split amongst six separate areas: transport security, compiler protection, UIWebViews, data storage, logs and binary analysis. Serious weaknesses were found in all of these areas.
40% of the applications can’t validate to the authenticity of SSL certificates, meaning that they’re vulnerable to monkey/man in the middle (MiTM) attacks

A full 90% of the apps contain non-SSL links, potentially allowing “an attacker to intercept the traffic and inject arbitrary JavaScript/HTML code in an attempt to create a fake login prompt or similar scam.”

50% “are vulnerable to JavaScript injections via insecure UIWebView implementations… allowing actions such as sending SMS or emails from the victim’s device.”

70% have no facility for any “alternative authentication solutions, such as multi-factor authentication, which could help to mitigate the risk of impersonation attacks.”

The incredibly troubling study brings to light a very serious problem for the banking industry — and for consumers, of course — that will only become more severe over time as mobile banking app usage grows. Sanchez notes in his report that the various security vulnerabilities he identified could allow malicious hackers to intercept sensitive data, install malware or even seize control of a victim’s device.

When Banks are using their mobile applications as a competitive advantage, you may think that they’d thoroughly test these applications for any existing security flaws with vulnerability assessment or mobile Penetration test, to reduce the vulnerabilities from two third to an acceptable level. Major security flaws shows that applications have not been tested for security vulnerabilities at every phase of the development. Above all it shows Banks have a weak Information Security Management System (ISMS) in place. This can be especially a worrisome trend for smaller Banks due to lack of existing information security resources and expertise.

Mobile Information Security and Privacy Books

Mobile Malware Protection from from phishing sites and malicious URLs

Tags: Banking Apps, Information Security Management System, SSL, Vulnerability (computing)


Jan 14 2014

What to Log for Authentication and Access Control

Category: Access Control,Log ManagementDISC @ 10:30 am

Authentication and access control plays a critical role in web application security.  Mostly for logging, all authentication and access control events should be logged which includes but not limited to successes and failures. If  we are logging only the successful events, someone may brute force attack the passwords without any detection or notice. On the contrary, let’s say only failures are logged, a legitimate or valid user may misuse, corrupt, harm or simply abuse the system without any detection. Besides that all other authentication and access control related events (such as account lockout) are important and must be logged.

  • Failed log in
  • Successful log in
  • Account locked /disable
  • Account unlocked / enabled
  • Account created
  • Password changed
  • Username changed
  • Logged out

Logs should include the resources involved in the web application (IP address, URL, user name, http method, protocol version, etc…) and document the reason why access was denied for the failed event. Some application provides much better logs than others. generally log entries should contain (user ID, timestamp, source IP, Description of the event, error code, priority).

All error conditions should be logged including simple stuff as sql query errors, which can help to detect sql injection attack. Some errors related to the availability of the application are important for early sign to trigger BCP. Availability is one of the main pillar of information security, so it should be logged and monitored. Log error conditions should include but not limited to (failed queries, file not found and cannot open error, unexpected state, connection failure and timeout)

Besides the inherent benefits of log management, a number of laws and regulations further compel organizations to store and review certain logs. The following is a listing of key regulations, standards, and guidelines that help define organizations’ needs for log management – ISO 27001, ISO 22301, FISMA, GLBA, HIPAA, SOX, and PCI-DSS.

Guide to Computer Security Log Management: Recommendations of the National Institute of Standards and Technology: Special Publication 800-92

Security Log Management

 

Tags: Access Control, authentication, Log Analysis, logging, Security, Site Management


Jan 06 2014

IT Governance Top 5 Bestsellers of 2013

Category: Information Security,ISO 27kDISC @ 11:24 am

With 2013 coming to a close, ITG is reflecting on what a year it’s been for the IT governance, risk management and compliance (IT-GRC) industry. In 2013  we’ve seen the highly-awaited release of ISO 27001:2013, the requirements for PCI DSS v3.0 and the Adobe breach which affected at least 38 million users.
Throughout it all, IT Governance has been there to serve IT professionals in America and assist them in implementing management systems, protecting their organizations and making their IT departments run more efficiently by implementing IT-GRC frameworks.
Below we have listed the top 5 IT Governance USA bestsellers from 2013:

ISO IEC 27001 2013 and ISO IEC 27002 2013
ISO 27001

Cyber Risks for Business Professionals: A Management Guide
CyberRisks

No 3 Comprehensive ISO27001 2005 ISMS Toolkit

ISMS toolkit

The True Cost of Information Security Breaches and Cyber Crime

Security Breaches

ITIL Foundation Handbook (Little ITIL) – 2011 Edition

ITIL

 

 

 

 

Tags: Corporate governance of information technology, Information Security Management System, Information Technology Infrastructure Library, ISO 27001 2013


Jan 04 2014

Hack-proof your life: A guide to Internet privacy in 2014

Category: Information PrivacyDISC @ 6:38 pm

privacy

A guide to Internet privacy

to a hack-proof Life

Keith Wagstaff NBC News

It’s no secret that 2013 wasn’t a great year for Internet privacy.
Former National Security Agency contractor Edward Snowden leaked thousands of classified documents that revealed the depths of the agency’s electronic surveillance program. Users had their information stolen en masse from private databases, including a security breach in November that reportedly resulted in 42 million unencrypted passwords being stolen from Australian-based Cupid Media, which was followed by a massive hack of Target credit and debit card information.
So, what’s a concerned netizen to do in 2014? Turns out there are plenty of ways to keep your data safe without breaking your Internet addiction.

Complete Guide to Internet Privacy, Anonymity & Security

Take two steps towards better security
Even if you aren’t worried about NSA agents reading your email, you should still be concerned about hackers taking a peek at your sensitive bank information or your “50 Shades of Grey” fan fiction.
That is why it’s a good idea to take advantage of two-step verification, something that Google, Facebook, Microsoft, Twitter and other companies have been pushing more often lately as big password leaks have hit the news.
Basically, not only will the service ask you for your password, but it will provide you with a code via a text message or an authentication app that will verify your identity.
“People should take the extra step because it’s incredibly effective in making it hard for someone to break into your account,” Yan Zhu, technologist for the Electronic Frontier Foundation, an advocate for Internet privacy, told NBC News. “They not only need access to something you know — which is your password — but they need access to something you own, which is your phone or another secondary device.”

Check your URL
Every website you visit should have “https” before the URL in the browser, instead of just “http,” to ensure Web traffic is encrypted for a more secure connection — especially in spaces with public Wi-Fi like airports and cafes. What do you do if that extra “s” is missing? You might want to install HTTPS Everywhere, a browser plug-in for Chrome, Firefox and Opera that rewrites requests to websites to keep you protected.
Change your terrible password
The top three passwords in a November security breach that reportedly affected 38 million Adobe customer accounts:
• 123456
• 123456789
• password
Not exactly impenetrable. And password cracking software — much of it freely available — is only getting more advanced. So how can you protect yourself?
“Use long passwords, at least eight characters, but the longer the better,” Maxim Weinstein, security advisor at Sophos, wrote to NBC News. “Avoid words (including names) and predictable patterns like adding a number to the end of a word. One trick is to choose a phrase or song lyric and use the first letter of each word (e.g., “Oh, say can you see, by the dawn’s early light” equals “oscysbtdel”), perhaps making some substitutions to make it more complex.”

Don’t use the same password for everything
You should also have a different password for every site, so that a hacker who gets your dating website password won’t all of a sudden have access to your Gmail account. Weinstein also recommended using a password manager like 1Password or LastPass to keep track of all of them, or, at the very least, creating three different passwords for your work email, personal email and websites that you visit.

Browse without being tracked
Normally, when you search for something on the Internet, the site can see what search term you used, not to mention your IP address, which can be used to identify you. Switching from your current search engine to one like DuckDuckGo is one step you can take to protect your identity.
“When you visit anything on the Internet, your computer is sending information about itself over the Net that can be used to tie things back to you. Most services store this information, which then can be used by these government programs and other things to identify you,” Gabriel Weinberg, the site’s founder and CEO, told NBC News. “DuckDuckGo, on the other hand, does not store any personally identifiable information, so we literally have nothing to tie your searches to you.”
When you are using Google, you can browse in Incognito mode. It doesn’t mask your searches or IP address, but it does have some added privacy benefits, like not recording your search history and deleting new cookies after you close your browser windows.

How to be Anonymous Online – A Quick Step-By-Step Manual

Consider the power of Tor
For the strictest level anonymity, you can download Tor, a software network that bounces Internet traffic around thousands of relays around the world to mask what sites you have visited and where you have visited them from. (Although, as the recent arrest of a Harvard student who allegedly used Tor while sending a fake bomb threat shows, it doesn’t guarantee you will be completely anonymous).

Encrypt your email
While free Webmail services like Gmail, Microsoft’s Outlook and Yahoo Mail have upped their encryption standards over recent years, you might still want the added protection of end-to-end encryption. It basically cuts out the middleman and sends email messages directly to the recipient, who can only read it if he or she has two encryption keys, one public and the other private.
“I really hope end-to-end encryption becomes more popular over the next year,” Zhu said. “One of the great things about it is that because it happens on the user’s computer, they have full control over it. They don’t have to trust a third party to keep their data safe.”
The downside? It’s not very easy to implement. Even Glenn Greenwald, the former Guardian reporter who broke the Edward Snowden story, had trouble with it. You’ll need to download encryption software called PGP (Pretty Good Privacy), or the open-source GPG (GnuPG), and start using an email client like Thunderbird. (The Press Freedom Foundation has a good explainer on how to set everything up). It’s all not very attractive or user-friendly — something that Mailpile, which raised $163,192 this year on Indiegogo, is hoping to change by developing a more Gmail-esque interface.

Protect your chats and cloud storage
Email isn’t the only personal data you should be worried about. Plenty of services store chat logs, and while cloud-storage services usually have strong protections, your information could still be at risk from hackers or anyone who has your username and password.
Some good solutions: Programs like Cryptocat or Pidgin with the OTR plug-in, for encrypted chats, and Cloudfogger or BoxCryptor for storing sensitive documents on services like Google Drive or Dropbox.

Of course, the reason people pick passwords like 123456 is because it’s easier than the alternative. If you want complete privacy and security in 2014, you’re going to have to work for it.


Dec 09 2013

Nine Steps to Success – An ISO 27001 2013 Implementation Overview

Category: ISO 27kDISC @ 1:17 pm

ISO 27001 2013-Perfect-Nine-Steps-Locked.indd

Nine Steps to Success – An ISO 27001(2013) Implementation Overview, Second Edition

Completely up to date with ISO 27001:2013, this is the new edition of the original no-nonsense guide to successful ISO27001 certification. Ideal for anyone tackling ISO 27001 for the first time, Nine Steps to Success outlines the nine essential steps to an effective ISMS implementation. Download your copy today!.

 

Step-by-step advice for ISO 27001 2013 project success

Based on his many years of first-hand experience with ISO27001, Alan Calder covers every single element of the ISO 27001 project in simple, non-technical language, including:

  • how to get management and board buy-in;
  • how to get cross-organizational, cross functional buy-in;
  • the gap analysis: how much you really need to do;
  • how to integrate with ISO9001 and other management systems;
  • how to structure and resource your project;
  • whether to use consultants or do it yourself;
  • the timetable and project plan;
  • risk assessment methodologies and tools;
  • the documentation challenges;
  • how to choose a certification body.

 

About the Author

Alan Calder is the Founder and Executive Chairman of IT Governance Ltd, an information, advice and consultancy firm that helps company boards tackle IT governance, risk management, compliance and information security issues. He has many years of senior management experience in the private and public sectors.

 


Dec 04 2013

ISO27001 2013 high level review for making the transition

Category: ISO 27kDISC @ 3:06 pm

ISO 27001 2013

ISO 27001 2013 high level review for making the transition from ISO 27001 2005

The Case for ISO 27001 (2013) Second Edition (Download the latest book in Adobe)

It’s been several months now that highly anticipated release of the latest information security standard ISO 27001 2013 for the organization who have vested interest due to previous compliance or certification in ISO 27001 2005. ISO 27001 2013 has 114 controls defined within 14 security control clauses (domains) collectively containing a total of 35 main security categories and introductory clauses including introduction, scope, normative references.

0. Introduction
1. Scope
2. Normative references
3. Terms and definitions
4. Context of the organisation
5. Leadership
6. Planning
7. Support
8. Operation
9. Performance evaluation
10. Improvement

The new standard no longer require organizations to adopt the Plan-Do-Check-Act (P-D-C-A) model to develop and introduce the ISMS, but leave it to each organization to determine and adopt a continual improvement model (corrective action) that works for them.

The scope in new standard requires every organization to make sure the external and internal issues, (vendor assessment) and information security requirements of these parties are addressed in the contract. This clause will ensure that an ISMS is relevant to the organization’s activity which include external partners and provides an assurance that appropriate controls are in place for external parties as well. In risk assessment area, risks are treated and residual risk accepted by risk owners rather than asset owners, which may require organizations to build a risk register, which will ultimately become an auditable document.

There is another important requirements relating to the setting of information security objectives (strategy), which include the evaluation of the information security performance and measuring the effectiveness of the ISMS.

Annex A has also been restructured into fewer controls (114) and three new domains
A.5. Information security policies
A.6. Organisation of information security
A.7. Human resources security
A.8. Asset management
A.9. Access control
A.10. Cryptography – new
A.11. Physical and environmental security
A.12. Operations security – new
A.13. Communications security
A.14. System acquisition, development and maintenance
A.15. Supplier relationships – new
A.16. Information security incident management
A.17. Information security aspects of business continuity management

The Standard now covers what was previously referred to as ‘control of documents’ and ‘control of records’ under the description of ‘documented information’.

There is no longer a summary of the mandated documents required by the Standard in this section, relying on the organization to identify the requirements for what is now referred to as ‘documented information’ for itself. They are listed below

The scope (4.3)
The information security policy (5.2 e)
The information security risk assessment process (6.1.2)
The information security risk treatment process (6.1.3)
Statement of Applicability (6.1.3 d)
The information security objectives (6.2)
Evidence of competence (7.2)
That documentation ‘determined by the organisation as being necessary for the effectiveness of the information security management system’ (7.5.1 b)
The documentation necessary to have confidence that the processes required for operational planning and control have been carried out as planned (8.1)
The results of information security risk assessments (8.2)
The results of information security risk treatment (8.3)
Evidence of the information security performance monitoring and measurement results (9.1)
Internal audit programme(s) and the audit results (9.2 g)
Evidence of the results of management reviews (9.3)
Evidence of the nature of the non-conformities and any subsequent actions taken, and the results of any corrective actions (10.1)

Summary of new controls in ISO 27001 2013 Annex A

A.6.1.5 – Information security in project management
All projects will address information security, regardless of the nature of the project. This ensures that information security is dealt with from the bottom up.
A.14.2.1 – Secure development policy
Rules for development of software and systems are established and applied to developments. This acts as a sort of precursor control to 14.1.1 and 14.1.3, which relate to controlling the data and applications developed under this control.
14.2.6 – Secure development environment
The organisation ensures an appropriately secure development environment for system development and integration, across the whole development lifecycle. This is deliberately broad to allow input from the earliest stages of the ISMS (identifying the nature of the organisation), rather than restrictively demanding measures that may not be relevant.
14.2.8 – System security testing
The organisation establishes acceptance testing programs and related criteria for new information systems, upgrades and new versions.
15.1.3 – Information and communication technology supply chain
This control requires agreements with suppliers to address information security risks associated with information and communications technology services and products supply chain.
16.1.4 – Assessment of and decision on information security events
Information security events are examined and assessed to determine whether they qualify as information security incidents. This control applies an additional step in the incident management process.

Contact DISC for a Free Gap Assessment for any domain of your choice based on location

Start your ISMS project with ISO27001 2013 Documentation Toolkit

Mapping of ISO/IEC 27001:2013 to ISO/IEC 27001:2005 for $6.99  

  

 Download ISO27000 family of information security standards!
• ISO 27001 2013 ISMS Requirement (Download now)
ISO 27002 2013 Code of Practice for ISM (Download now)

 

Tags: Information Security Management System, isms, ISO 27001 2013, ISO 27001 2013 Gap Assessment, ISO 27001 2013 Toolkit, iso 27001 certification, ISO 27001 Lead Implementer


Dec 01 2013

ISO27001 2013 ISMS Standalone Documentation Toolkit

Category: ISO 27kDISC @ 9:53 pm

ISO27001 2013

Start your ISMS project with ISO27001: 2013

With the publication of the new version of the ISO27001 standard, there has never been a better time to start an ISMS implementation project to look after your information security.

 

ITGP toolkits – ISO27001: 2013 ISMS Documentation Toolkit

This new Toolkit provides you with a comprehensive set of pre-written ISMS documents compliant with the newly released ISO27001: 2013 Standard, built from the necessary policies, procedures, work instructions and records that will save you months of work as you get your information security system up to speed, including:

* Information Security Manual

* Visio Documentation Map and Structure

* Information Security Policy

* vsRisk risk assessment tool Integration Templates (not vsRisk itself)

* Business Continuity Management for information security

* Gap analysis ISO27001: 2013 and ISO27002: 2013 Audit tool

* Asset Management documentation templates such as, Asset Inventory, Information Hardware Assets, Software log, etc.

* Supplier Relationships documentation templates such as, External Parties Information Security Procedure and Third Party Service Contracts

* Operations and Communications Security document templates dealing with, Anti-Virus Software, Vulnerability Management, Systems Auditing, System Planning & Acceptance, etc.

 

Benefits of the ISO27001: 2013 ISMS Documentation Toolkit:

  • Fully customisable and editable templates inclusive of:
    7 Policies, 55 Procedures, 23 Work Instructions, 25 Records, guidance documents as well as Blank Templates that will enable you to bring in your exisitng documentation in-line with a consistent management system
  • Pre-written to be compliant with the standard
  • Saves you time on research
  • Saves you time on writing
  • Provides document guidance as you go
  • Cheaper than one day of consultancy
  • After sales support service
  • 12 months of automatic updates

 

Related articles

Tags: ISO 27001 2013, ISO 27001 2013 Gap Assessment, ISO 27001 2013 Toolkit


Nov 26 2013

New IT-GRC Glossary designed to simplify industry terms

Category: IT GovernanceDISC @ 11:29 am

Glossary_banner

New IT-GRC Glossary from IT Governance designed to simplify industry terms

IT Governance Ltd, the single source provider of IT governance, risk management and compliance (IT-GRC), has just published a glossary on their website.

The IT-GRC glossary is designed to help IT professionals recognize the wide range of acronyms used within the industry to further their understanding and avoid confusion.

Currently there are 70 terms in the glossary and IT Governance is looking to grow this significantly. IT Governance is encouraging readers to contribute to the glossary with new terms or refined definitions so that the glossary continues to develop and become a resource for IT professionals to use worldwide.

The glossary contains a wide range of IT governance terms, including information security, business continuity, quality management, IT service management and IT governance topics. The glossary is arranged alphabetically and provides easy-to-use definitions that drop down when clicked. The definitions have been written and edited by industry experts and link to information pages for further guidance. View the glossary:

Founder and Executive Chairman of IT Governance Ltd, Alan Calder, explains the reasons behind developing the glossary: “The industry within which we operate in contains a huge number of shortened phrases and acronyms which can be somewhat confusing for those starting out in their career. With different associations, institutions, standards, frameworks and certificates to remember, we decided it was important to start documenting these terms so that beginners would have a useful source to refer to.”

This new resource further strengthens the IT Governance mission statement of “approaching IT from a non-technology background and talking to management in their own language”. The glossary reduces industry jargon and simplifies terms for IT professionals.

The glossary has been added to the growing number of resources offered from IT Governance, which includes a wide number of green papers, product demos and case studies – all which are freely available to download.

Tags: Dictionaries, Governance risk management and compliance, GRC, Risk management


Nov 19 2013

Everything you require for COBIT5 implementation

Category: IT GovernanceDISC @ 10:25 am

COBIT5

 

Are you implementing, or thinking about implementing, the COBIT 5 framework?

ITG COBIT bookstore includes all the titles you’ll need to help support your implementation of COBIT 5 and get the most out of this IT governance control framework.

COBIT 5 Publication Suite

COBIT 5 Publication Suite

All the currently-available core COBIT 5 books in one handy kit. The COBIT 5 Publication Suite includes COBIT 5, COBIT 5: Enabling Processes and COBIT 5 Implementation.

Governance and Internal Controls for Cutting Edge IT

Governance and Internal Controls for Cutting Edge IT

A guide to optimising resources and minimising risk, using the COBIT 5 framework to establish appropriate standards of security for the introduction of new technology.

COBIT 5 for Information Security

COBIT 5 for Information Security

In this manual you will be shown how the relevant frameworks, best practices and standards for information security can be adapted to form a cohesive framework using COBIT 5.

IT Governance Control Framework Implementation Toolkit

IT Governance Control Framework Implementation Toolkit

The Governance & Control Toolkit has been designed to help simplify the complex implementation of COBIT 5. Containing all the documents and policy templates you’ll need to cover the 37 COBIT processes this toolkit will dramatically speed up your implementation project.

Visit ITG webshop to view wide range of COBIT 5 resources >>>


Nov 05 2013

When can we become certified to ISO/IEC 27001:2013?

Category: ISO 27kDISC @ 8:39 pm

ISO 27001

ISO27001:2013

 ISO27001: 2013 – order your copy today >>>

When can we become certified to ISO/IEC 27001:2013?

by Lewis Morgan @ ITG

At this moment in time, we can only provide an estimate which is based on the insight provided by Chair of the UK ISO/IEC 27001 User Group and Director of consultancy at IT Governance Ltd, Steve Watkins. Considering Steve’s position, we believe his estimates to be the best guidelines an organization can follow.

The following is directly taken from the ISO27001:2013 Transition Webinar by Steve Watkins

“It’s likely that as of 1st January 2014, certification bodies will be able to start the transition to the 2013 version of ISO27001 standard. If that is indeed the case, it’s likely to be that as of 30th September, no new ISO27001:2005 certificates can be issued. This means that by the end of September 2016 all ISO27001:2005 certificates should have transitioned to the 2013 version of the standard”

The image below further illustrates what Steve discussed on the webinar, including his suggestions in terms of what organizations should do next.

ISO27k timeline

Tags: Information Security Management System, ISO, ISO/IEC 27001


Oct 18 2013

10 Steps To Assess Cyber Security Risk

Category: cyber security,Risk AssessmentDISC @ 9:00 pm

cyber attack ...  Economic Pearl Harbor Will S...

October is National Cyber Security Awareness Month and it is an opportunity to engage public and private sector stakeholders – especially the general public – to create a safe, secure, and resilient cyber environment. Everyone has to play a role in cybersecurity. Constantly evolving cyber threats require the engagement of the entire nation — from government and law enforcement to the private sector and most importantly, the public.

National Cyber Security Awareness Month

A cyber security risk assessment is necessary to identify the gaps in your organisation’s critical risk areas and determine actions to close those gaps. It will also ensure that you invest time and money in the right areas and do not waste resources where there is no need for it.

Even if you have implemented an ISO 27001 Information Security Management System, you may want to check if your cyber security hygiene is up to standard with the industry guidelines. 

Cyber Security ToolKit  | Cyber Security Standards | Cyber Security Books

Cyber security risk assessment:

Use an in house qualified staff or an experienced consultant(s), who will work with your team to examine each of the ten risk areas (described below) in sufficient detail to identify strengths and weaknesses of your current security posture. All this information can be consolidated and immediately usable action remediation plan that will help you close the gap between what you are actually doing and recognized good practice. It will enable you to ensure that your cyber risk management at least matches minimum industry guidelines.

The ten risk areas that will be examined are:

Do you have an effective risk governance structure, in which your risk appetite and selected controls are aligned? Do you have appropriate information risk policies and adequate cyber insurance?

Do you have a mobile and home-working policy that staff have been trained to follow? Do you have a secure baseline device build in place? Are you protecting data both in transit and at rest?

Do you have Acceptable Use policies covering staff use of systems and equipment? Do you have a relevant staff training programme? Do you have a method of maintaining user awareness of cyber risks?

Do you have clear account management processes, with a strong password policy and a limited number of privileged accounts? Do you monitor user activity, and control access to activity and audit logs?

Do you have a policy controlling mobile and removable computer media? Are all sensitive devices appropriately encrypted? Do you scan for malware before allowing connections to your systems?

Do you have a monitoring strategy? Do you continuously monitor activity on ICT systems and networks, including for rogue wireless access points? Do you analyze network logs in real time, looking for evidence of mounting attacks? Do you continuously scan for new technical vulnerabilities?

Do you have a technical vulnerability patching program in place and is it up-to-date? Do you maintain a secure configuration for all ICT devices? Do you have an asset inventory of authorized devices and do you have a defined baseline build for all devices?

Do you have an appropriate anti-malware policy and practices that are effective against likely threats? Do you continuously scan the network and attachments for malware?

Do you protect your networks against internal and external attacks with firewalls and penetration testing? Do you filter out unauthorised or malicious content? Do you monitor and test security controls?

Do you have an incident response and disaster recovery plan? Is it tested for readily identifiable compromise scenarios? Do you have an incident forensic capability and do you know how to report cyber incidents?


Sep 25 2013

Be the first to receive ISO/IEC 27001:2013

Category: ISO 27kDISC @ 6:25 pm

ISO 27001

ISO27001:2013 Now Available!

Be the first to receive ISO27001: 2013 – order today >>>

ISO27001: 2013 is the new standard that details the requirements for an information security management system (ISMS).

ISO270012013

ISO/IEC 27001 2013 (ISO27001 ISO 27001) ISMS Requirements

There a several updates to the new standard including:

• Terms and definitions are now referenced from ISO27000:2012 (with the terminology of ISO27000 also being updated)
• Risk assessment requirements are less prescriptive and are now aligned with ISO 31000 – the international standard for risk management.
• The PDCA cycle is no longer mandated as the approach for reviewing and improving an ISMS. You can use the PDCA or any other approach.
• The requirements for management commitment have been overhauled and are largely contained presented in the Leadership clause
• The requirements for a statement of applicability in the 2013 edition have been enhanced
• The risk treatment process makes it easier to adopt control frameworks other than Annex A
• Annex B has been deleted, and Annex A has also been revised and restructured
Be the first to receive the new ISO27001:2013 standard.

The Code of Practice for Information Security Controls, ISO27002 has also been updated.
ISO/IEC 27002:2013 establishes guidelines and general principles for initiating, implementing, maintaining, and improving information security management in an organization.
Order ISO27002:2013 today >>>


Aug 15 2013

Cyber Security Governance & Risk Management Toolkit

Category: cyber securityDISC @ 9:56 am

Cyber Security Toolkit

The threat from cyber space is real and growing.
To strengthen cyber security in your organization, there are several frameworks you can adopt:

• ISO/IEC 27001
• ISO/IEC 27032
• PAS 555
• the BIS Ten Steps to Cyber Security
• the Cloud Security Alliance’s Cloud Control Matrix

These standards and guidance offer, between them, a comprehensive cyber security umbrella for your organization.

This is the only toolkit to consolidate the advice from the five leading approaches to managing cyber risk into a single, robust framework, and is made up of:

  • ISO27001 Documentation Toolkit – which will enable you to achieve external certification.
  • Independently developed Cyber Security Documentation – offering the guidance you need to put in place effective processes to achieve cyber resilience.
  • Documentation drawing on PAS 555, BIS Ten Steps, Cloud Controls Matrix and ISO27032 – extending the controls contained in ISO27001, and enhances the benefits of implementing an ISO27001 ISMS.
  • Cyber Security Framework Matrix – efficiently mapping the five separate approaches to a single comprehensive, robust, framework.
  • Bring Your Own Device (BYOD) Toolkit – these templates will enable your organization to benefit from improved productivity, reduced capital expenditure and a better work life balance for employees.

The Cyber Security Governance & Risk Management Toolkit consolidates the advice from these five leading approaches to managing cyber risk into a single, robust framework.

This toolkit helps you make an enormous leap forward by consolidating five
separate approaches into a single, comprehensive, robust framework.

Cyber Security Toolkit

Get your copy and start your cyber resilience project today!

Cyber Security Governance & Risk Management Toolkit


Aug 07 2013

vsRisk – The Cyber Security Risk Assessment Tool

Category: ISO 27k,Security Risk AssessmentDISC @ 9:09 am

vsRisk – The Cyber Security Risk Assessment Tool

httpv://www.youtube.com/watch?v=M8acvay4FmU

It is extremely difficult to carry out a risk assessment that will meet the requirements of ISO27001 without using a specialist information security risk assessment tool. While there are a wide range of products on the market that claim to meet these requirements, the reality is that there are very few.

There’s just one risk assessment tool that IT Governance recommends; the vsRisk™ v1.7 – the Cybersecurity Risk Assessment Tool.

It’s so straightforward, and so quick to use, it can save you a significant amount of the budget you might otherwise spend on consultancy advice at this stage of the project.

5 reasons why vsRisk is the definitive risk assessment tool:

  • This tool automates and delivers an ISO/IEC 27001-compliant risk assessment
  • Can uniquely assess confidentiality, integrity & availability (CIA) for each of business, legal and contractual aspects of information assets – as required by ISO27001
  • Gives comprehensive best-practice alignment
  • It’s easy and straight-forward to use
  • Cost-effective route to assessing risks within your business

Download the definite risk assessment tool >>

 

Tags: Information Security, Information Security Management System, ISO/IEC 27001, Policy, Risk Assessment, Risk management, Security, Standards


« Previous PageNext Page »