Jul 22 2013

Your employees aren’t the only threat to InfoSec and Compliance

Category: cyber security,Information SecurityDISC @ 1:18 pm
Information security

Information security (Photo credit: Wikipedia)

July 22nd, 2013 by Lewis Morgan 

I overheard a conversation the other day, one which left me so stunned that I’ve decided to write about it….

Two men having dinner behind me (I got the impression they were both directors) were discussing the £200k fine the NHS received for losing patient data. Eventually, the conversation turned into a discussion about information security as a whole. I won’t go into all the details but one of them said, “We don’t particularly focus on cyber security, it’s always large organisations which are in the news about getting hacked and being a small company, we’re not under threat”. It bothered me (probably more than it should have) that someone in control of an organisation has that attitude to cyber security. If an organisation of 5 employees was hacked, the same day as, let’s say DELL, were hacked – who’d make it into the news? DELL would, why? Because it’s likely to be more of an interest to the readers/listeners and will have a bigger impact on the public compared to that of the smaller organisation.

I never see stories in the news of someone being hit by a bus in my local town, but it doesn’t mean I’ll walk in front of one holding a sign saying ‘hit me’. That’s effectively what this director is doing, turning a blind eye to a large threat just because he’s not seen an example of a small organisation being hacked – chances are he doesn’t even read the publications which cover those stories.

Ignorance

It’s a strong word, isn’t it? Personally I hate calling people ignorant, I’d rather use a more constructive word such as ‘unaware’, but I feel that using the word ignorance will raise some eyebrows.

As a director of a company, your aim is to maximise revenue, minimise costs and anything in between.

You need a future for your organisation; this is usually done by investing in your marketing efforts, improving your products/services and providing the best customer service possible. But what do you do to actually secure a future? It’s all good and well having a 5 year plan which see’s 400% growth in revenue, but how do you make sure that your organisation will even exist in 5 years?

2 years into your plan and you’re hitting your targets – but you’ve just discovered that there’s been a data breach and your customers credit card details have been sold online.

Your plans have now become redundant; they are depending on how prepared you are to handle the situation, so are your staff. The cost of recovering from a data breach for a small organisation is between £35 – 65K (and that’s not including fines). Can your organisation afford that? Probably not, but you could have afforded the costs which would have prevented this breach in the first place.

Let’s say that the breach happened because a new member of staff was unaware that they shouldn’t open emails in the spam folder. An email was opened, malicious software was installed and login credentials were stolen. You could have trained that member of staff on basic information security in under an hour, for £45. But instead, you chose to ignore your IT Manager who’s been raising spam issues at each monthly meeting but all you chose to hear is “we’ve not been hacked” and “invest” which is enough for you to move on.

What your IT Manager is really telling you is “We’ve recently been receiving a large amount of emails into our spam filter, and some are getting through. I think we need to invest in a more advanced spam filter, and perhaps train some of the staff on which emails to avoid. A virus from an email could lead to a hack, it’s not happened yet but there’s a chance it will.”

Forget blaming the IT Manager or the new member of staff when that breach happens, it comes down to you and your:

Inability to perceive cyber threats

Grey areas in appropriate knowledge

Naivety

Overhead cost restrictions

Refusal to listen to something you don’t understand

Absent mindedness

No interest in the customer’s best interests

Careless decisions

Eventual disaster

 

Cyber security threats are real, so why are you ignoring them?

To save money? Tell that to a judge

Introduction to Hacking & Crimeware

You don’t understand the threats? Read this book

 

Tags: Computer security, data breach, Email spam, hackers, Information Security, Malware


Jul 15 2013

Boardroom Cyber Watch Report 2013

Category: cyber securityDISC @ 9:23 am

Cyber-Watch-2013-sml

Download the ‘Boardroom Cyber Watch Report 2013’ Free!

  • Almost 75% of respondents say their customers prefer to deal with suppliers with proven IT security credentials;
  • 50% say customers have enquired about their company’s security measures in the past 12 months.

 

The ‘Boardroom Cyber Watch 2013’ is the first survey IT Governance has undertaken which specifically targets chief executives, board directors and IT professionals. Our aim is to shine new light on how company directors and board members currently perceive IT security issues as well as to provide them with practical guidance on how to address these challenges.

Boardroom Cyber Watch Report 2013

Boardroom Cyber Watch Report 2013

Price: FREE PDF Download

Learn more

Tags: Canadian Cyber Incident Response Centre, Computer security


Jul 12 2013

Final Draft of New ISO 27001 Standards Now Available

Category: ISO 27kDISC @ 9:55 am

The ISO/IEC announced this week that the latest ISO 27001 and ISO 27002 Standards have entered the Final Draft stage (FDIS). This means that the standard is almost ready for publication, with no, or only minor changes to be made in the final approval stage.

IT Governance is offering you the chance to get ahead of the game and purchase copies of these new ISO 27001 standards today.

 

ISO/IEC FDIS 27001 2013

ISO/IEC FDIS 27001 2013

Price: $160

Buy Now

ISO/IEC FDIS 27002 2013

ISO/IEC FDIS 27002 2013

Price: $240

Buy Now


Jun 25 2013

Risk management – ISO 27005 could be the cure

Category: ISO 27k,Risk AssessmentDISC @ 9:30 am

English: ISMS activities and their relationshi...

English: ISMS activities and their relationship with Risk Management (Photo credit: Wikipedia)


 
 
 
 
 
 
 
 
 
 
 
 
 
 

By Catherine Thornley @ ITG

Risk management in information security management and how ISO/IEC 27005 can help you tackle it effectively.

Risk is arguably one of the most commonly used words in business, but what does it actually mean?

There are many English dictionary definitions, many centered around “a situation involving exposure to danger” and whilst some people talk about up-side or positive risk, it is generally accepted that in business, the risk is all about the chance that something will go wrong, and how badly.

But of course there is uncertainty in everything we do; and therefore risk. Sometimes there is uncertainty about whether something good will happen, but that just means that there is also a chance that it won’t; which is bad.

Risk and corporate governance

The big thing about risk in business today is corporate governance. People responsible for running companies are simply not allowed, when something goes wrong, to say “we didn’t think of that”, or “it never happened before”. Those are two quite common responses both when something has gone wrong and also when it hasn’t; when senior managers are asked to do something about risk management.

For many, when they do finally look at risk, thinking switches immediately from chance to result. The likely impact of a risk dominates thinking where previously it was the probability of a threat materialising that was the dominant factor.

Many organisations assess risk intuitively; that is to say they simply decide whether an activity, or situation, is very risky, not very risky, or somewhere in between.

This intuitive approach can be applied to information security risk – but it can be very difficult to evaluate risk effectively in this area. The challenge is two-fold; understanding what information security actually is and knowing how to assess and respond to the related risks in a logical way, that will stand scrutiny should the worst happen.

Information security managers, and those doing the job as part of a broader role, often need some help in identifying the most effective way to manage this specific set of risks, which is where ISO 27005 can help.

How ISO 27005 can help

Where ISO 27001 presents a broad blueprint for dealing with information security, ISO 27005 takes it much further and delivers the detail of information security risk assessment, in a way that the results integrate easily into an ISO 27001 compliant information security management system (ISMS).

ISO 27005 provides a detailed and valuable insight into effective information security risk management. And since ISO 27001 calls for a risk based approach, there cannot be a better basis for it!

 5 reasons why vsRisk v1.6 is the definitive risk assessment tool


Jun 15 2013

Unreasonable searches and drone killings

Category: Information Privacy,Security and privacy LawDISC @ 1:52 pm
Search

Search (Photo credit: ~FreeBirD®~)

Peter Scheer @ SFChronicle.com on June 12, 2013 – Open Forum on NSA’s snooping

First came news accounts of the government’s use of armed drones in the targeted killing of terrorists abroad. Then came the revelations about government surveillance programs, breathtaking in their scale, tapping into data on phone calls, e-mails, Internet searches and more.

These activities are, in fact, linked.

The use of drones to target America’s enemies represents the fruition of technological evolution in weapon accuracy. Though America’s previous military conflicts have been characterized by military strategies that often maximized enemy casualties (think of the “body counts” during the Vietnam War), the technology of drones makes possible the highly discriminate targeting of selected individuals, with minimal civilian casualties.

U.S. intelligence gathering has evolved in the opposite direction. Before data mining, and especially before the end of the Cold War, intelligence gathering was focused narrowly on selected institutions or individuals. America knew who its enemies were; the objective of espionage operations, from wiretaps to infiltration by American spies, was to find out what they were doing: with whom they were communicating, their capacities and plans.

In recent years, by contrast, the focus has shifted to intercepting and analyzing mountains of data in order to discern patterns of activity that could lead to the identification of individual enemies. Intelligence gathering has evolved from the penetration of known groups or individuals to the sifting and mining of Big Data – potentially including information on all U.S. citizens, or all foreign customers of Google, Facebook, et al. – in order to identify individuals or groups that are plotting attacks against Americans.

The logic of warfare and intelligence has flipped. Warfare has shifted from the scaling of military operations to the selective targeting of individual enemies. Intelligence gathering has shifted from the targeting of known threats to wholesale data mining for the purpose of finding terrorists.

The resulting paradigms, in turn, go a long way to account for our collective discomfort with the government’s activities in these areas. Americans are understandably distressed over the targeted killing of suspected terrorists because the very individualized nature of the drone attacks converts acts of war into de facto executions – and that, in turn, gives rise to demands for high standards of proof and due process.

Similarly, intelligence activities that gather data widely, without fact-based suspicions about specific individuals to whom the data pertain, are seen as intrusive and subject to abuse. The needle-in-a-haystack approach to intelligence gathering is fundamentally at odds with Americans’ understanding of the Constitution’s promise to safeguard them against “unreasonable” government searches. There is nothing reasonable about giving government secret access to phone calls and e-mails of tens of millions of Americans.

Our fear of these changes is reinforced by the absence of transparency surrounding drone strikes – specifically, the protocols for selecting targets – and intelligence operations that cast a broad net in which U.S. citizens are caught. This is why Americans remain supportive of, and thankful for, an independent and free press.

Peter Scheer, a lawyer and writer, is executive director of the First Amendment Coalition. FAC has filed suit against the U.S. Justice Department for access to classified legal memos analyzing the use of drones to target suspected terrorists. The views expressed here are Scheer’s alone and do not necessarily reflect the opinions of the FAC board of directors.

Unreasonable Searches and Seizures: Rights and Liberties
under the Law (America’s Freedoms)

Tags: Big Data, Data mining, First Amendment Coalition


Jun 12 2013

Why you should care about your digital privacy?

Category: Information Privacy,Information SecurityDISC @ 4:25 pm
English: Infographic on how Social Media are b...

English: Infographic on how Social Media are being used, and how everything is changed by them. (Photo credit: Wikipedia)

Surveillance Countermeasures

When we use internet browser for a web search, social media site, communication (skype), buy something from a site, we are leaving digital tracks all over the internet. Your service provider of the above services have access to this information because they are collecting  this treasure trove to identify and figure out what you like and don’t like so they can serve you appropriate ads and services accordingly. Most importantly they want to know that what you may buy or do next on the internet.

Well now we know that our government is utilizing that data as well from these providers to figure out if you may have some ties with the bad elements out there. To elaborate a bit at this point, for example, if a bad guy call you and left a message on you voice mail, you are presumed guilty by association and you and your friends may come under heavy surveillance after this incident.  So far all this collection and analysis of data has been done without your knowledge and permission.

As Mark Zukerberg said that Facebook only provide information which is required by law. Well in this case the law (PRISM) wants everything without warrant. By using social media we create a treasure trove of data, which can be analyzed to figure out patterns, one may deduce what that person may do next. You may want to remember that when you post next time on a social media.

Tags: Business, facebook, Internet Marketing, PRISM, Social media, Social network, Twitter, YouTube


Jun 06 2013

10 tips to prevent mobile malware

Category: Mobile SecurityDISC @ 10:38 am
Mobile Malware

Mobile Malware (Photo credit: IntelFreePress)

By Vanja Svajcer, SophosLabs

How do you prevent it? By taking back control of your devices and their applications.

Here are 10 tips for securing your mobile users and preventing mobile malware infections.

1. Inform users about mobile risks

A mobile device is a computer and should be protected like one. Users must recognize that applications or games could be malicious, and always consider the source. A good rule of thumb: if an app is asking for more than what it needs to do its job, you shouldn’t install it.

2. Consider the security of over-the-air networks used to access company data

Generally speaking, over-the-air (i.e., Wi-Fi) networks are insecure. For example, if a user is accessing corporate data using a free Wi-Fi connection at an airport, the data may be exposed to malicious users sniffing the wireless traffic on the same access point. Companies must develop acceptable use policies, provide VPN technology, and require that users connect through these secure tunnels.

3. Establish and enforce bring-your-own-device (BYOD) policies

BYOD should be a win-win for users and companies, but it can result in additional risk. Ask yourself: How do I control a user-owned and managed device that requires access to my corporate network? Employees are often the best defense against the theft of sensitive data. Employees using their own mobile devices must follow policies that keep the business compliant with regulatory requirements.

4. Prevent jailbreaking

Jailbreaking is the process of removing the security limitations imposed by the operating system vendor. To “jailbreak” or to “root” means to gain full access to the operating system and features. This also means breaking the security model and allowing all apps, including malicious ones, to access the data owned by other applications. In brief, you never want to have root-enabled devices in your company.

5. Keep device operating systems up to date 

This sounds easier than it actually is. In the Android ecosystem, updates can be blocked a number of ways: by Google (which updates the operating system); by the handset manufacturer (which may decide to release updates only for the latest models); or by the mobile provider (which may not increase bandwidth on their network to support updates). Without the ability to update your Android OS, your device is vulnerable to potential exploits. Research mobile providers and handset manufacturers to know which ones apply updates and which don’t.

6. Encrypt your devices

The risk of losing a device is still higher than the risk of malware infection. Protecting your devices by fully encrypting the device makes it incredibly difficult for someone to break in and steal the data. Setting a strong password for the device, as well as for the SIM card, is a must.

7. Mobile security policies should fit into your overall security framework

IT needs to strike a balance between user freedom and the manageability of the IT environment. If a device does not comply with security policies, it should not be allowed to connect to the corporate network and access corporate data. IT departments need to communicate which devices are allowed. And you should enforce your security policy by using mobile device management tools.

8. Install apps from trusted sources; consider building an enterprise app store

You should only permit the installation of apps from trusted sources, such as Google Play and Apple App Store. However, companies should also consider building enterprise application stores to distribute corporate custom apps and sanctioned consumer apps. Your chosen security vendor can help set up an app store and advise which applications are safe.

9. Provide cloud-sharing alternatives

Mobile users want to store data they can access from any device, and they may use services without the approval of IT. Businesses should consider building a secure cloud-based storage service to accommodate users in a secure way.

10. Encourage users to install anti-malware on their devices

Although malware exists for iOS and BlackBerry, those operating system interfaces don’t support anti-malware. However, the risk of infection is highest for Android, where security software is already available. Make sure all your Android devices are protected by anti-malware software.

Hacking Exposed Mobile Security Secrets & Solutions


Jun 05 2013

CyberWar, CyberTerror, CyberCrime

Category: cyber security,CybercrimeDISC @ 10:14 am

CyberWar-CyberCrime-CyberCrime

Cyber wars between companies, hacker groups and governments can force entire countries to a standstill. A lone, but sophisticated, hacker can bring global organisations to their knees from just an internet café. The threat isn’t even entirely external; perhaps the greatest threat sits uncomfortably in plain sight – from inside your staff.  Arm yourself with the top cyber security titles:

CyberWar, CyberTerror, CyberCrime

This book is written by Dr Julie Mehan who is a Principal Analyst for a strategic consulting firm in the State of Virginia. She has been a Government Service employee, a strategic consultant, and an entrepreneur – which either demonstrates her flexibility or inability to hold on to a steady job! Until November 2007, she was the co-founder of a small woman-owned company focusing on secure, assured software modernization and security services. She led business operations, as well as the information technology governance and information assurance-related services, including certification and accreditation, systems security engineering process improvement, and information assurance strategic planning and programme management. During previous years, Dr Mehan delivered information assurance and security-related privacy services to senior department of defence, federal government, and commercial clients working in Italy, Australia, Canada, Belgium, and the United States.

Here are the contents of this book.

The world is becoming ever more interconnected and vulnerable, as has been demonstrated by the recent cyber attacks on Estonia. Thus the need for stringent and comprehensive methods for combating cyber crime and terror have never before been need more than now.
Information security should not be an after thought. It should be ingrained into the organisation’s culture. This book will help you create this forward thinking culture using best practices and standards.
Key Features:

  • Straightforward and no-nonsense guide to using best practices and standards, such as ISO 27001, to instil a culture of information security awareness within an organisation.
  • Distils key points on how to use best practices and standards to combat cyber crime and terror.
  • The information within the book is presented in a straightforward and no-nonsense style, leading the reader step-by-step through the key points.

 

 

What other people say about this book:
So what you have in CyberWar, CyberTerror, CyberCrime is a skillful blend of very readable, at times even entertaining and certain to stimulate introspection, guidance on just why and how cyber security is important to every organization connected to the internet – try to name one that is not .  I would bet that truly effective leaders will purchase multiple copies and circulate CyberWar, CyberTerror, CyberCrime throughout the entire organization.
Leonard Zuga, Partner, Technology and Business Insider (TBI)
 

“This book is a good basis for a security roadmap. It’s well researched and well written.”

Peter Wood, Chief of Operations at First Base Technologies

 

“This is a book that I will look forward to using to enhance both my undergraduate and graduate instruction in information security.”

Dr Bob Folden, Assistant Professor, Business Administration and MIS, Texas A&M University – Commerce

 

“This is an interesting book that introduces the reader to the security of the Internet industry, goes into some details on how some abuse it. This is a very good book. You will enjoy it.”

Jerome Athias, Computer Security Researcher


May 21 2013

Cyber Security Risk Governance and Management

Category: cyber securityDISC @ 11:33 am

 

PAS 555 – Cyber Security Risk Governance and Management

ITG-RiskGovernance

What does effective cyber security look like?

The many standards and sources of best practice on cyber security tend to focus on delivery (the how).

PAS 555:2013 is the new Cyber Security Risk Governance and Management standard, and details what effective cyber security looks like (the what).

PAS 555:2013 Cyber Security Risk Governance and Management

PAS 555 is intended for use by any organization that wishes to gain confidence in their management and governance of cyber security. Any organization irrespective of their size, type, nature of business or location can employ the PAS 555.

Simply buy the standard and get started with delivering effective cyber security today!


May 20 2013

A Guide to Data Security and ISO27001/ISO27002

Category: ISO 27kDISC @ 1:39 pm

ITGovernance

IT Governance 5: An International Guide to Data Security and ISO27001/ISO27002

This manual provides clear, unique guidance for both technical and non-technical managers. It details how to design, implement and deliver an ISMS that complies with ISO 27001.

Now in its fifth edition, this title has been fully updated to take account of the latest regulatory and technological developments, and the International Board for IT Governance Qualifications

 

Tags: Corporate governance of information technology, Information Security, Information Security Management System, ISO, ISO/IEC 27001, Risk Assessment


Apr 23 2013

Cyber Security and Risk Assessment

Category: cyber security,Security Risk AssessmentDISC @ 9:19 am

Cyber security is the protection of systems, networks and data in cyber space.

If your system is connected on the internet, you should know and uderstand the risks of cyber space to take appropriate countermeasures.

To understand the risks of cyber security,The first place is to begin with is a risk assessment. By completing a risk assessment you can understand what the risks, threats and vulnerabilities of your networks, systems and data really are and begin to comprehend how to reduce and handle them. The authors of The Information Security Risk Assessment Toolkit provides handy step-by-step guidance on how to undertake a risk assessment. As we said Security Risk Assessment is an important first to assess risks but the second step of mitigating those risks in timely manner is crucial to protect your information assets.

Once you understand what the risks of your business are, you can then decide on how to mitigate those risks based on your organization risk acceptance.

Tools and techniques which work in mitigating cyber risks

The UK’s Cyber-security Framework for Business (published by the Department for Business, Innovation and Skills) is a 10-step framework to stop around 80% of today’s cyber-attacks
1. Board-led Information Risk Management Regime
2. Secure Home and Mobile Working
3. User Education and Awareness
4. User privilege management
5. Removable media controls
6. Activity monitoring
7. Secure Configurations
8. Malware protection
9. Network security
10. Incident Management

Build the resilience in your information security management system (ISMS) to cope with the other 20% of the risk.

The authors of Hacking 7 Exposed cover the latest methods used by third-parties to (logical/physical) access to information assets. They then detail how you can protect your systems, networks and data from unauthorised access.

Cybersecurity standards are an important element in building a strong, resilient information and communications infrastructure. ISO/IEC 27001 is the most significant international best practice standard available to any organisation that wants an intelligently organised and structured framework for tackling its cyber risks

Tags: Computer security, cyberwarfare, Information Security, Information Security Management System, Risk Assessment, Risk management


Apr 15 2013

Implications of becoming a cybersecurity victim

Category: cyber securityDISC @ 7:17 pm

What are the potential implications of becoming a cybersecurity victim?

  • PWC/DTI Information Security Breaches Survey 2012
    • 93% large businesses suffered security incident last year
    • Average cost of worst incident for large business £110k to £250k
    • The average large organisation had 71 security breaches in the previous year, up from just 45 two years previously.
  • National High Tech Crime Unit survey 2004
    • Of 201 respondents 167 (83%) experienced high-tech crime in 2003
    • Impact of these crimes > £195million

Online, Keep Safe Resources

Below are some free online resources which any smaller business or home owner will find useful:

Safeguard your computer

* Workstations should be set up in a secure, clean, calm, stable environment.

* Don’t have loose cables that might be a safety hazard; tripping over a cable and pulling it out of the computer

*  Always log out of and shut down Windows, and switch your computer off when it’s not in use.

* The biggest risk associated with laptops (also known as notebooks) is, in fact, the loss or theft of the laptop.

The Essential Guide to Home Computer Security

Tags: Computer security, National Institute of Standards and Technology


Apr 12 2013

Exploding the myths surrounding ISO9000

Category: Information SecurityDISC @ 10:05 am

Español: NORMAS ISO

Exploding the myths surrounding ISO9000 (Adobe eBook)

Thousands of companies worldwide are reaping the benefits from implementing the ISO9000 Quality Management standard. However, there are many conflicting opinions about the best approach. Some companies have delayed applying the standard, or have chosen not to implement it at all. This might be because of a lack of time and resources to investigate it properly, or because of misunderstandings about the way it works. So, how do we know who and what to believe?

The secrets of successful ISO9000 implementation

In Exploding the Myths Surrounding ISO9000, Andrew W Nichols debunks many of the common misconceptions about the standard, and describes the many advantages it brings. Drawing on more than 25 years of hands-on experience, Andy gives clear, practical and up-to-date advice on how to implement ISO9000 to maximum effect. Full of real-life examples, this book will enable you to:
• read and interpret the ISO9000 documentation in order to realize its benefits for your company
• estimate your company’s implementation needs
• benefit from the results of this management system as positive change is effected throughout the company and down the supplier chain
• increase efficiencies and reduce waste
• grow sales as you understand and meet your customers’ needs

Read this unique book and make ISO 9000 work for you.

iso9000

Tags: International Organization for Standardization, ISO 9000, Quality management, Quality management system


Apr 03 2013

IT Governance 5 top tips for Implementing successful ISO27001

Category: ISO 27kDISC @ 11:06 am

Nine Steps to ISO27001

  1. Get a copy of the standard! There are a few people out there that purchase the standard half way through implementation (or even not at all) but the truth of the matter is, this is one of the first things you should do. It will help confirm suspicions and will be the core backbone as to what you do from now on.
  2. Get management buy in. This is critical for supporting your ISO27001 project and making it a success
  3. Read, read, read! There’s a wealth of free information out there on the web to help you get stuck in to your ISO27001 project. From white papers to Linkedin groups, you’re sure to find what you’re looking for.
  4. Use all the available tools and resources out there. This will make implementation a lot easier, saving you lots of head scratching, late nights and hours spent staring out the window! Documentation toolkits really help simplify the process and can also lessen the time it takes you to reach certification
  5. Communication is at the heart of the ISO27001 process. It allows you to keep your Board and the rest of your organisation updated with regular progress reports and key measurements to indicate the success of the project so far.

 

Nine Steps to Success: an ISO 27001 Implementation Overview This is the ideal guide for anyone tackling   – or about to tackle – ISO27001 for the first time.


Mar 28 2013

Top Five IT Governance Titles

Category: Information Security,IT GovernanceDISC @ 12:18 pm

Download one of IT Governance industry leading ebooks. IT Governance source and publish titles on cyber security, compliance, project management, risk and  IT service management.

Fantastic Reads… All Better Priced Than Amazon

Learn and stay ahead on your topic of choice. download an ebook today!

Running IT like a Business: A Step-by-Step Guide to Accenture's Internal IT

ISO22301 A Pocket Guide

ISO22301: A Pocket Guide is designed to help you do what is necessary to satisfy the requirements of ISO22301. With the expert advice contained in this guide, you can ensure your organisation develops a business continuity plan that is fit for purpose.


30 Key Questions that Unlock Management

30 Key Questions that Unlock Management

30 Key Questions that Unlock Management is a book that provides direct responses to real questions posed by real people in management. Each section contains practical advice and immediate steps you can take to deal with the issue at hand.


Managing Business Transformation: A Practical Guide Managing Business Transformation: A Practical Guide

Brush up on your soft skills and see the working relationships with your IT Audit clients flourish. Exploring how and why an auditor can remain trapped in an ascribed role, this book fills a gap in the market by helping the reader to avoid the traditional finger-pointing stance and instead become a convincing partner with business and technology counterparts.


Running IT like a Business: A Step-by-Step Guide to Accenture's Internal IT Running IT like a Business: A Step-by-Step Guide to Accenture’s Internal IT

Running IT like a Business will show you how your IT function can add real value to your business, taking guidance from Accenture who doubled its revenue in ten years. With clear strategies, helpful diagrams and real-life examples, this book will give you the keys to unlocking your IT function’s hidden potential.


Agile SPA

Agile SAP

Understand how to bring your SAP projects in on time and within budget with the help of this guide, written by Project Management Professional and Certified ScrumMaster, Sean Robson.


Mar 28 2013

Compartmentalizing and Segmenting Privileged Passwords

Category: Access ControlDISC @ 9:34 am

Privileged Password

By Liberman Software @ Identity Week

If you’re a fan of old war movies – and especially if you’re a child of the Cold War – then you no doubt recall watching scenes where prior to launching a nuclear missile, two operators will turn their launch keys simultaneously in order to initiate the launch. The military refers to this security process as “The Two Person Concept” or “The Two Man Rule”. Sometimes the phrase “Double Safekeeping” is used.

The concept is that double safekeeping is an effective control mechanism for ensuring the highest levels of security during critical operations. That’s because the process requires two or more authorized personnel to be involved before sensitive resources or information can be accessed.

So it’s only logical to assume that if double safekeeping can prevent something as crucial as the accidental or malicious launch of nuclear weapons by a single person, then the practice can be extended into other realms of security.

Double Safekeeping and Privileged Account Management

And that’s exactly what my company did recently within the field of privileged account management. Our flagship privileged identity management product, Enterprise Random Password Manager™ (ERPM), now includes a version of double safekeeping that controls privileged passwords.

ERPM is a security product that automatically discovers, secures, tracks and audits privileged accounts across multiple operating systems. It continuously changes privileged passwords, and helps prevent unauthorized users and programs from being able to access an organization’s most sensitive data.

Now, with its new double safekeeping feature, ERPM can release different password segments to different authorized IT personnel. It breaks up privileged account passwords into different parts, and each part is assigned to an authorized user, in a fully audited manner.

For example, an IT manager may have one segment of the password, and a systems administrator may have the other segment. Together both people have the entire password, and the ability to access the corresponding privileged account. Separately, neither one can use the powerful account to anonymously change configuration settings, extract confidential data or install programs on their own.

And while this may be the first time you’re hearing about such a capability, I’m betting it won’t be the last.  Some regulatory compliance mandates, like BASEL II, are now requiring organizations to store sensitive information – including passwords – in multiple parts so that one person can’t maintain key secrets individually.

This whole thing reminds me of an old saying that goes something like: “If one man can single handedly save the ship, then it stands to reason that the same man can also single handedly sink the ship.” Take precautions.

 

Tags: Password, Password manager, Privileged Identity Management, Two-man rule


Mar 11 2013

IT Governance announces the release of BYOD Toolkit

Category: BYODDISC @ 9:40 pm
byod policy

BYOD Policy Template

IT Governance the global leader in information security and compliance solutions, has released a BYOD Policy Template Toolkit. BYOD (Bring Your Own Device) promises improved productivity, reduced capital expenditure and better work-life balance for employees. It also promises security and compliance problems for organisations that have inadequate BYOD policies. Organisations can use this easy-to-customise BYOD policy template, and its supporting ‘Acceptable Use Agreement’, to structure, focus and document their own organisational approach to BYOD, and to get informed sign-up from every employee who wants to benefit from a BYOD option. Fully up-to-date for the March 2013 official guidance on data management and security from the UK’s Information Commissioner, this BYOD Policy Template Toolkit puts affordable best-practice at the fingertips of CIOs and Security Managers everywhere. This toolkit is compatible and can be used within an ISO27001 Information Security Management System (ISMS) and also reflects the requirements of the Business Continuity Management Standard, ISO22301.

Organisations will benefit from implementing BYOD Policy by:

  •   shifting investment and running  costs to the employee
  •   boosting employee satisfaction
  •   speeding up use within the organisation of cutting edge technology
  •   eliminating end-of-life device administration.

To purchase this extremely cost-effective, easy-to-use and DPA-compliant toolkit, visit

 


Mar 06 2013

Your Cyber Security Project

Category: cyber securityDISC @ 12:04 pm

by James Warren

Internet technologies have revolutionised the way that business is conducted but these innovations expose your business to various cyber security risks.

Inadequate security can lead to the theft of customer data and, in the event of technological failure or a cyberattack, your business could lose its ability to function altogether. An effective risk management strategy is, therefore, vital to your company’s survival.

Cyber Security Risks for Business Professionals: A Management Guide Cyber Risks for Business Professionals: A Management Guide 

A general guide to the origins of cyber security risks and to developing suitable strategies for their management. It provides a breakdown of the main risks involved and shows you how to manage them.

Cybersecurity standards are an important element in building a strong, resilient information and communications infrastructure. ISO/IEC 27001 is the most significant international best practice standard available to any organisation that wants an intelligently organised and structured framework for tackling its cyber risks. As the leading provider of cyber security products and services, ITG can help you with any aspect of your project:

Cyber Security Risks for Business Professionals: A Management Guide  >> ITG | eBay | Amazon

Tags: Computer security, cyber security, Information Security, ISO/IEC 27001, Risk management


Mar 02 2013

Forward-thinking books on information security

Category: Information Security,ISO 27kDISC @ 8:01 pm

unto the breach

Forward-thinking books on information security help organisations understand current challenges in the sector

/EINPresswire.com/ Keeping up-to-date with information security issues and responding to new cybersecurity challenges can be time-consuming. However, it is essential that anyone concerned with information security, from IT professionals through to the Board members, dedicates time to learning and understanding these issues.

Last week, for example, the UK’s National Audit Office highlighted a severe lack of skilled cybercrime fighters in the UK. Cybercrime is costing the UK economy an estimated £18-27 billion each year.

So, is there a fast route to getting up to speed with what’s happening and what the modern means are to fight cybercrime?

Information security experts at IT Governance advise there is an easy way to catch up with the latest developments and fill in the knowledge gap. They recommend three essential books that can greatly improve everyone’s understanding of information security, data protection and risk management, whilst providing them with enjoyable and useful reading.

Once more unto the Breach – Managing information security in an uncertain world is based on a typical year in the life of an information security manager. The book examines how the general principles can be applied to all situations and discusses the lessons learnt from a real project. The book can be purchased as softcover and eBook from >> Once more unto the Breach – Managing information security in an uncertain world 

IT Governance – An International Guide to Data Security and ISO27001/ISO27002 is the definitive guide to implementing an ISO27001 compliant Information Security Management System (ISMS). Written by industry experts, Alan Calder and Steve Watkins, it contains clear guidance on all aspects of data protection and information security. Book reviewers describe it as ‘unparalleled’, a critical source when preparing and managing the ISMS’ and ‘a comprehensive guide as to actions that should be taken’. The book can be ordered online at >> IT Governance – An International Guide to Data Security and ISO27001/ISO27002

Managing Information Security Breaches – Studies from real life provides a general discussion of, and a source of learning about, what information security breaches are, how they can be treated and what ISO27001 can offer in that regard, spiced with a number of real-life stories of information security incidents and breaches. This book is highly relevant and will help every team to prepare a strategic framework for handling information security breaches. Buy a softcover or eBook from >> Managing Information Security Breaches – Studies from real life

 


Feb 28 2013

Cutting edge titles for IT professionals

Category: Information SecurityDISC @ 10:37 am

IT professionals

IT Governance Publishing (ITGP) are at the forefront of sourcing and publishing cutting-edge titles in the cyber security, compliance, business continuity and IT service management sectors. ITGP top 10 cutting-edge latest titles.

 

ISO22301 A Pocket Guide

This handy pocket guide explains what the ISO22301 Business Continuity Standard is and how to start planning a Business Continuity Management System (BCM) that complies with this international standard.
Buy Today »

Ten Steps to ITSM Success

This book provides guidance on implementing ITSM Best Practices in an organisation using an easy to follow ten step approach.
Buy Today »

30 Key Questions that Unlock Management

A direct response to real questions posed by real people doing real jobs. Each section contains practical advice and immediate steps you can take to deal with the issue at hand.
Buy Today »

The Quantum Age of IT

‘Charles has really nailed it for any executive struggling with IT strategy. How IT got here and where it’s going.’ – Randy Steinberg, Author, ITIL Service Operation, 2011 Edition, Principal – Migration Technologies.
Buy Today »

Running IT Like A Business

Running IT like a Business will show you how your IT function can provide much more than products and services and add real value to your business.
Buy Today »

Exploding the Myths Surrounding ISO9000 – A Practical Implementation Guide – Published 25th March

In this book management systems expert Andrew Nichols, who has over 25 years industry experience, explains in detail how to implement ISO9000 to maxium effect.
Buy Today »

ITIL and Organizational Change – Published 5th March

Thousands of organisations every year adopt ITIL, however many fail to achieve significant benefits. This book examines how to avoid common pitfalls and how to clear the many hurdles that can obstruct progress.
Buy Today »

Governance and Internal Controls for Cutting Edge IT – Published 5th March

Based on practical experience and real-life models, this new book covers key principles and processes for the introduction of new technologies and examines how to establish an appropriate standard of security and control.
Buy Today »

ITIL Lifecycle Essentials – Published 28th March

This book doesn’t just cover the information required to pass the foundation exam, but goes beyond this in providing practical guidance for when newly qualified practitioners enter the real-world.
Buy Today »


« Previous PageNext Page »