Jul 30 2012

Six main benefits of Information Security Management System

Category: ISO 27kDISC @ 3:11 pm

 

Information Security Wordle: RFC2196 - Site Se...

Information Security Wordle: RFC2196 - Site Security Handbook (Photo credit: purpleslog)

 

1. Business managers of the organizations will make informed decisions regarding potential risk and should be able demonstrate compliance with standards and regulations such as SOX, GLBA, HIPAA, DPA to their critical information on regular basis.

2. An ISMS is a defensive mechanism to any APT (advanced persistent threat) to minimize the impact from these external threats of various cybercrime.

3. Informed information security decisions will be made based on risk assessment to implement technical, management, administrative and operational controls, which is the most cost effective way of reducing risk. Highest priority risks are tackled first to attain best ROI in information security.

4. Information security is not an IT responsibility; In general everybody in an organization is responsible for protecting information assets and more specifically business manager. The business manager may delegate their responsibility.

5. Organization will improve credibility and trust among internal stakeholder and external vendors. The credibility and trust are the key factors to win a business.

6. ISMS raises awareness throughout the business for information security risks, involve all employees throughout an organization and therefore lower the overall risk to the organization.


Jul 11 2012

Comprehensive business continuity guide

Category: BCPDISC @ 3:01 pm

IT Governance Publishing, the specialist publishing arm of IT Governance, has launched its latest book on business continuity and disaster recovery planning Everything you want to know about Business Continuity

The book focuses particularly on the new ISO/IEC 22301:2012 standard and provides practical guidance on how to implement best practice business continuity management within your organisation.

Everything you want to know about Business Continuity will show you how business continuity management can help your organisation to:

    * Carry out realistic risk identification and assessment and focus on assets which need BCP
    * Put in place a cost-effective, ‘fit-for-purpose’ business continuity plan to be more competitive
    * Enjoy greater customer loyalty and return on investment
    * Conform to the legal requirements in terms of accountability, compliance, risk awareness
    * Return to ‘business as usual’ as quickly as possible after an unforeseen incident.

The author, Tony Drewitt, held a number of technical, commercial and senior management positions before becoming a full-time management consultant 10 years ago. He was one of the first consultants in the UK to achieve full certification under BS25999-2 and has been a practising business continuity consultant, trainer and technical expert since 2001.


Jul 03 2012

Information Security Awareness

Category: Security AwarenessDISC @ 2:06 pm

Managing an Information Security and Privacy Awareness and Training Program


Jun 27 2012

Download the full version of the ITIL and/or ISO27001 toolkit today!

Category: ISO 27kDISC @ 2:01 pm

Over the past several months IT Governance has been telling us about two of their most popular toolkits – the ITSM, ITIL and ISO20000 Implementation toolkit and the Standalone ISO27001 ISMS Documentation Toolkit.

You may have already downloaded free demo versions of these toolkits, in which case now is the perfect time to download the full version.

ITSM, ITIL® & ISO/IEC 20000 Implementation Toolkit
This toolkit is a collection of documents (policies, procedures and work templates) that will make IT Service Management easier to implement and improve.

Buy the full version here >>

Standalone ISO27001 ISMS Documentation Toolkit
The toolkit is a collection of documents (policies, procedures and work templates) that will ensure your Information Security Management System (ISMS) paperwork is in line with the requirements of ISO27001.

Buy the full version here >>

Tags: iso20000, ISO27001, ITIL


Jun 19 2012

Achieve Best Practice & Win New Business with International IT Standards

Category: cyber security,ISO 27kDISC @ 3:38 pm

International IT Standards help organizations achieve best practice systems and management of their IT processes. Certification against standards can help organizations protect their critical assets, rebuff cyber attacks, help win new business and achieve compliance against regulatory requirements.

ISO27001: Cyber Security Standard (Cheapest price on the web)
ISO27001 helps businesses create a best in class Information Security Management System (ISMS), safeguarding its information assets, protecting its reputation
.
ISO22301: Business Continuity Standard (Published last Month)
ISO22301 sets out the requirements for a Business Continuity Management System (BCMS) and helps organizations ensure they are prepared should an disruptive incident occur, and more importantly, continue trading and return to business as usual as quickly as possible

ISO20000: IT Service Management Standard (Best Seller)
ISO20000 enables IT organizations (whether in-house, outsourced or external) to ensure that their IT service management processes are aligned. This standard specifies the requirements for an service management system (SMS). This standard will help you develop, implement, establish an SMS.

Tags: BCMS, isms, iso 27001, iso20000, ISO22301, SMS


Jun 04 2012

Learn how to tackle the Flame

Category: cyber security,CybercrimeDISC @ 9:25 pm

A vicious piece of malware (known as Flame) was uncovered this week and is believed to have infected over 600 targets, be 20 times larger than Stuxnet and to have been backed by state sponsorship.
Realize the underground economy of hacking and crimeware with this handy pocket guide. It will provide you with a valuable list of up-to-date, authoritative sources of information, so you can stay abreast of new developments and safeguard your business.

An Introduction to Hacking & Crimeware: A Pocket Guide (eBook)

Know your enemy: An Introduction to Hacking & Crimeware is a comprehensive guide to the most recent and the more serious threats. Knowing about these threats will help you understand how to ensure that your computer systems are protected and that your business is safe, enabling you to focus on your core activities.

Fighting back
In this pocket guide, the author:

• defines exactly what crimeware is – both intentional and unintentional – and gives specific, up-to-date examples to help you identify the risks and protect your business
• explores the increasing use of COTS tools as hacking tools, exposing the enemy’s tactics gives practical suggestions as to how you can fight back
• provides a valuable list of up-to-date, authoritative sources of information, so you can stay abreast of new developments and safeguard your business.


May 27 2012

Social Engineering: An essential book and must have competency

Category: social engineeringDISC @ 11:11 pm

Chris Hadnagy has a website on the topic of Social Engineering and assisted in developing Social Engineering Toolkit (SET). This topic and knowledge apply to every person who keep sensitive information and organization who want to protect private information leakage into public domain via people. If you are interested in knowing the art of social engineering, this is an outstanding book.

Hadnagy recommends tools to store information you obtain during target investigation. He covers Google hacks in this book and mentioned Johnny Long as a source. He covers pretexting (disguise) or “creating an invented scenario to persuade a target victim to release information or perform some action.” He provides preparation tools for social engineer for the situation at hand and also warns you about legality if you are crossing the line. There is an important section on “Building Instant Rapport” which is an essential read. Hadnagy describe the powers of persuasion to take over the target and provides eight tactics for influencing people.

Social Engineering: The Art of Human Hacking“, by Chris Hadnagy is a must have book.”

Discover the secrets of expert con men and human hackers

No matter how sophisticated your security equipment and procedures may be, their most easily exploitable aspect is, and has always been, the human infrastructure. The skilled, malicious social engineer is a weapon, nearly impossible to defend against.

This book covers, in detail, the world’s first framework for social engineering. It defines, explains, and dissects each principle, then illustrates it with true stories and case studies from masters such as Kevin Mitnick, renowned author of The Art of Deception. You will discover just what it takes to excel as a social engineer. Then you will know your enemy.

  • Tour the Dark World of Social Engineering

    Learn the psychological principles employed by social engineers and how they’re used

    Discover persuasion secrets that social engineers know well

    See how the crafty crook takes advantage of cameras, GPS devices, and caller ID

    Find out what information is, unbelievably, available online

    Study real-world social engineering exploits step by step

  • Get your copy today Social Engineering: The Art of Human Hacking


    May 25 2012

    10 essential books for IT Professionals

    Category: Information SecurityDISC @ 11:54 am

    All books are available in softcover, eBook and Kindle-compatible formats at a better price than Amazon! *

    Below are 10 latest publications from IT Governance:

      1)      30 Key Questions that Unlock Management
    by Brian Sutton and Robina Chatham
         

     

      2)      The Concise PRINCE2
    by Colin Bentley
         

     

      3)      50 Top IT Project Management Challenges
    by Premanand Doraiswamy and Premi Shiv
         

     

      4)      Everything you wanted to know about Business Continuity
    by Tony Drewitt
         

     

      5)      Everything you wanted to know about Agile
    by Jamie Lynn Cooke
         

     

      6)      Cloud Computing: Assessing the Risks
    by Jared Carstensen, Bernard Golden and JP Morgenthal
         

     

      7)      The ITSM Iron Triangle: Incidents, Changes and Problems
    by Daniel McLean
         

     

      8)      Managing Business Transformation: A Practical Guide
    by Melanie Franklin
         

     

      9)      Running IT like a Business: Accenture’s Step-by-Step Guide
    by Robert E. Kress
         

     

      10)  21st Century Chinese Cyberwarfare (Pre-order)
    by Lieutenant Colonel Hagestad

     
     
     


    May 21 2012

    Organisations can achieve ISO9001 QMS certification quicker with a bespoke toolkit

    Category: Information SecurityDISC @ 1:40 pm

    Check out the ITG site for details

    Ely, England, 21 May 2011 – IT Governance Ltd, the global leader in management system standards, information, books and tools, is advising organisations that the quicker they implement the Quality Management System standard ISO9001, the bigger their chances are to attract new customers in the current economic conditions.

    Vendors who have been asked by their clients to implement the ISO9001 standard can now achieve this quickly and effectively by using the ISO9001 QMS Quality Management System Documentation Toolkit. It contains over 60 separate documents that will help organisations accelerate the development and implementation of an ISO9001 quality management system. The toolkit can be downloaded immediately here: QMS-ISO9001 Toolkit

    ISO9001 is the best practice specification that helps businesses and organisations throughout the world to develop a best-in-class Quality Management System (QMS). According to BusinessLink UK Government more than 1 million organisations are currently certified against ISO9001. The advantages to businesses from implementing ISO9001 include:

    •greater efficiency and less waste
    •consistent control of major business processes, through key processes lists
    •regulation of successful working practices
    •risk management
    •increased customer satisfaction
    •greater consistency in the quality of products and services through better control of processes
    •differentiation of your business from its competitors
    •increased profits

    The ISO9001 QMS Toolkit, developed by IT Governance, contains a quality management manual, and a full set of policies and procedures, in addition to the necessary forms, records and work instructions to underpin those policies and procedures. It is the complete toolkit for implementing an ISO9001 quality management system.

    ISO9001 in Plain English

    Tags: iso 9001, QMS


    May 13 2012

    The Cybersecurity Risk Assessment Tool

    Category: ISO 27k,Security Risk AssessmentDISC @ 9:24 pm

    With over 10 years in the market and 2,500 global downloads, vsRiskTM has been helping organizations all over the world carry out successful risk assessments.
    Risks assessment is the core competence of cyber security management. Every decision you make must be proportionate to the actual risk your organization faces. You must therefore assess risks on a structured asset-by-asset basis – and experience proves you need to save time and money with a risk assessment tool that automates and simplifies this process.
    vsRisk is the definitive ISO27001:2005-compliant risk assessment tool which will help you become cybersecure

    vsRisk – The Definitive Cyber Security Risk Assessment Tool
    The vsRisk Assessment Tool has been designed with the user in mind to effectively identify, analyze and control their actual information risks in line with their business objectives. Key features of vsRisk include:
    • Assessing key areas such as Groups, Assets and Owners
    • Capturing your IS policy, objectives and ISMS scope
    • In-built audit trail and comparative history
    • Assessesing attributes on Confidentiality, Integrity, and Availability, in relation to Business, Legal, Contractual
    • Comprehensive reporting and gap analysis

    Alan Calder, CEO of Vigilant Software, talks you through the risk assessment process using vsRisk
    Watch the video now >>>

    This unique risk assessment tool helps you get on top of the critical risk assessment phase of your ISMS project and, most importantly, sets you up for future risk assessments as well.
    Join the professionals and orders your today >>>

    vsRisk and Security Risk Assessment


    Apr 29 2012

    Is ISO 27001 Worthwhile for Your Business?

    Category: ISO 27kDISC @ 9:31 pm

    ISO 27001 As A Business Tool
    More than ever, information security is a key part of a business’ overall plan and objective set. ISO 27001 can help businesses bring their information security practices together and develop a strategy to raise awareness and vigilance throughout the business.

    With ISO 27001, all of a business’ information security is brought together, meaning there is a far greater level of accountability across all levels of the organisation.

    ISO 27001 is a highly worthwhile tool, a world leading information security management system which integrates compliance into an organisation’s everyday tasks.

    Who Is Accountable For ISO 27001?
    The short answer is everybody, however there is more to it than that. ISO 27001 stands alone as an information security standard as it places the sole accountability on the business managers. That is, ultimately the buck stops with them, however it is up to them to spread responsibility and delegate as they see fit.

    It is down to the business leaders to clearly identify which information security risks apply to their particular business and then take the necessary action to remove the risk entirely, or reduce it to a workable, acceptable level. It is the full responsibility of the managers to check and maintain that ISO 27001 standards are being met across the business.

    One aspect which makes ISO 27001 a highly worthwhile tool is that there is room for each business to implement the standard in a way that best suits them. This is far removed from previous standards which have been “blankets”, leading to businesses at times putting things in place when in reality that scenario will never apply to them.

    ISO 27001 is only really worthwhile if a business and its leaders gives the necessary level of time and dedication to achieving its aims. The certificate of ISO 27001 is an acknowledgement that an information security management system exists, continuous work must be done to ensure that compliance standards are continually met and the business remains fully protected.

    Strong Reputation
    A business with an ISO 27001 certification will be highly reputable so long as the standards required are strongly upheld. A dedication to the protection of information, whether it be internal finances or customer details, is highly regarded throughout the world in an age where privacy is highly valued but not often respected.

    ISO 27001 raises awareness throughout the business of information security risks, involves all employees throughout a company and therefore delivers a significantly lower level of overall risk.

    Tags: iso 27001, iso 27002


    Apr 18 2012

    Risk Assessment control selection and cost savings

    Category: Risk Assessment,Security Risk AssessmentDISC @ 10:13 am

    In risk management, risk treatment process begins after completion of a comprehensive risk assessment.
    Once risks have been assessed, risk manager utilize the following techniques to manage the risks

    • Avoidance (eliminate)
    • Reduction (mitigate)
    • Transfer (outsource or insure)
    • Retention (accept and budget)

    Now the question is how to select an appropriate control to avoid or reduce risk. While selecting appropriate control to mitigate and avoid risk we need to consider compensating control to cut cost and supplemental control to increase protection for sensitive or classified assets.

    Compensating control is a safeguard or countermeasure is employed by an organization in lieu of recommended security control from standards such as ISO 27002 or NIST 800-53. Compensating control provides an equivalent or comparable protection for information system to the original control requirement form standard. For example, even though most standards recommend separation of duties, but for a small operation it might be an unacceptable cost to separate the duties of system administration and system auditing. In that case system owner can utilize compensating control such as strengthening the audit and personnel security.

    On the other hand with supplemental control, the system owner may decide to supplement the control to achieve more protection for sensitive and classified assets. If there is high likelihood or magnitude of impact is high should a threat exploit a given vulnerability you might want to consider a supplemental control because overall risk is high. For example you might want to utilize defense in depth method to safeguard your crown jewel.

    Implementing and monitoring security control can be expensive, system owner are pressured by management to look for cost savings without any reduction in the security posture of an organization. The system owner can either inherit the common controls or segment the system exposure to reduce cost and risks.
    Common controls are the security controls which have been implemented by another information system that your system can utilize. Basically working with another system owner who has utilized some of the security controls need to be implemented in your system. For example utilize the corporate office base line hardening configuration for Windows and Unix system instead of developing your own. This will significantly reduce the cost of developing, testing and maintaining a secure baseline configuration.

    Best and cheapest method of cost reduction is to segment the information system into multiple systems which will add different layers and levels of security into each system. Basically you put your crown jewel in multiple layers of security if one control breaks there is another control in place to monitor and protect your assets. This will allow the system owner to focus implementing higher security controls to the segment with most sensitive or classified information instead of entire system


    Apr 10 2012

    The world’s only cyber security standard

    Category: ISO 27kDISC @ 12:03 pm

    ISMS Requirements

    Boardrooms are finally waking up to the importance of cyber security. In the digital age, winning new business, protecting your own assets and ensuring customer confidence are all dependent upon cyber security. And there is one international standard which can help you achieve all of this, ISO27001.

    But what do you really know about the ISO27001 Standard?
    ISO27001 is the international best practice standard for an information security management system (ISMS). An ISMS is a systematic approach to managing all your confidential and sensitive information so that it remains secure, whilst maintaining its availability, confidentiality and integrity.
    An ISMS encompasses people, processes and IT systems and ensures your security efforts and coherent, effective and proportionate. ISO27001 provides the requirements to help you design a best in class ISMS.

    If you are new to ISO27001 you can read more information and download a free white paper on cyber security and ISO27001 here >>>

    Download a copy of ISO 27001 ISMS Requirements


    Mar 26 2012

    IT Governance helps SMEs protect themselves from cybercrime

    Category: ISO 27kDISC @ 1:45 pm

    Check out the ITG site for details

    IT Governance Ltd, the global provider of cyber security management solutions, has announced a value-add offer in March. Organisations that buy the No3 ISO27001 Comprehensive Toolkit before the end of March will receive the Cybersecurity Self Assessment Tool free, making double savings on resource and time.

    The No3 ISO27001 Comprehensive Toolkit contains highly practical books, document templates and risk assessment tool, also providing a 100% return on investment. It helps organisations tackle cybersecurity issues quickly and efficiently, whilst considerably improving their cybersecurity defences.

    The recent Symantec Threat Awareness Survey uncovered that over 50% of the 1,900 SME’s interviewed, thought that they were immune to cybercrime because they were too small.

    However, Symantec’s report found that since 2010 40% of all attacks were on SME’s. Ross Walker, Symantec director of small business for Symantec UK, commented “hackers are going after ‘low hanging fruits’ these are the companies who are less security aware and do not have the proper defences in place”.

    Alan Calder, CEO of IT Governance, says “The best way to build robust and effective cyber defences is by implementing ISO27001, the world’s cybersecurity standard. An ISO27001-compliant Information Security Management System (ISMS) promotes customer confidence, helps vendors win new business and improves organisational efficiency”.

    The easiest way to implement an ISO27001-compliant ISMS, especially for SMEs, is with the No 3 Comprehensive ISMS ISO27001 Toolkit. It provides organisations with all the tools they will need for the implementation of an information security management system (ISMS).

    The No 3 Comprehensive ISMS ISO27001 Toolkit includes copies of the three key standards (ISO27001, ISO27002 and ISO27005), the Risk Assessment Tool (vsRisk™), the Documentation Template Toolkit and manuals that describe in practical detail how each aspect of the ISMS should be tackled.

    One user of the Toolkit said: “Using the templates was the only way that we could deliver a first edition ISMS in under six months. Our deliverable was a work in progress, but miles ahead of where they would have been without the templates”.

    Organisations that buy the No 3 Comprehensive ISMS ISO27001 Toolkit before the end of March will receive the Cybersecurity Self Assessment Tool free. It enables any organisation to quickly assess and demonstrate which areas of the organisation are up to scratch and where more attention is required.

    Organisations can purchase the ISO27001 Comprehensive Toolkit here!

    Tags: Information Security Management System, isms, iso 27001, iso 27002, ISO 27004, iso 27005, iso 27006, iso27003


    Mar 20 2012

    Risk Management and Business Life Cycle

    Category: Security Risk AssessmentDISC @ 1:29 pm

  • Risk management is a business process and all the business decisions should have a business development life cycle
  • Risk management is a management responsibility, must be supported by senior management and that concept of Ownership of assets must be established
  • In Pre screening of critical assets, assets sensitivity must be established based on business, legal and contractual values for confidentiality, integrity and availability. this risk analysis process will determine which critical assets needs to go through the risk assessment process
  • Organizaions use risk assessment to determine what threats exist to a specific asset and the associated risk
  • The risk acceptance threshold will provide the organization with the information needed to select effective control measures or safeguards to lower the risks to an acceptable level
  • Risk is a function of the probability that an identified threat will occur and then the impact that threat will have on the asset
  • Risk Assessment should include the followings primary steps:
    * Critical Asset Sensitivity (impact analysis) level affecting business, contractual and legal imapct
    * Threats identified
    * Vulnerabilities related to the threats
    * Probablity of occurance that the specific threat will exploit the given vulnerability
    * Impact of the loss if the specific threat will exploit the given vulnerability
    * Risk level identified
    * Control recommendations based on risk acceptance
    * Results documentation

    How to Complete a Risk Assessment in 5 Days or Less

    Tags: Risk Assessment, Security Risk Assessment, Tom Peltier


    Mar 10 2012

    Security Controls and Principles

    Category: Information SecurityDISC @ 11:01 pm

    For security controls to be effective, apply the pillars of information security

    — Principle of least privilege
    — Separation of duties
    — Economy of mechanisim
    — Complete mediation
    — Open design

  • Least privilege is Need to Know principle or default deny -essentially, don’t permit more then required to meet the business requirement to avoid extra risk
  • For separation of duties we don’t want to give any individual so much control that they become a security risk without proper check and balance inplace
  • The principle of economy of mechanism basically says that more complexity we introduce into security system, creates potential for failures
  • Complete Mediation says that control cannot be bypassed – no unofficial back doors
  • Open design – the securty of the system must not be based on the obscurity of the mechanism
  • Information Security: Principles and Practice


    Mar 02 2012

    What makes a good Information Security Policy?

    Category: Security policyDISC @ 12:50 pm

    Good policies should have five distinct attributes to become a successful and reasonably accepatable organization wide.

    Specific: A policy must address a specific issue or objective clearly and thoroughly.

    Measureable: To be effective, policy must have some condition of measuring adherence to the control. If people are not adhereing to policy then we may need better controls or perhaps better training program.

    Achievable: To follow the policy, employee must have enough resources, tools and training to make policy objectives achieveable

    Realistic: How realisticcally can we expect the policy will be followed and employee will be able to achieve his/her business objectives without any issues. This is where there is a need to balance security and availability. The question we need to ask how much should we Lock it Down or Free it Up?

    Time Based: Specify when policy takes effect, when review will occurs and when conformance become required

    To remember these five attributes here is an acronym “SMART”

    Writing Information Security Policies


    Feb 23 2012

    21st Century Chinese Cyberwarfare

    Category: cyber securityDISC @ 2:21 pm

    The UK’s 2010 National Security Strategy identified cyberattacks as one of the four highest-priority risks faced by the UK. President Obama has declared cybersecurity as one of the most serious economic and national security challenges the US faces as a nation.

    There is an Advanced Persistent Threat (APT) posed by organised crime and state level entities, targeting large multi-national corporations and foreign governments. Organisations of all sizes can suffer collateral damage. China has been regularly identified in the press as a major player in modern cyberwar activities but, until now, little has been written to describe the depth and severity of this threat.

    21st Century Chinese Cyberwarfare, from IT Governance Publishing, is a comprehensive and in-depth review of the Chinese role in cyberwarfare. Drawing on a combination of cultural, historical, business, linguistic and personal experience, the book attempts to explain China to the uninitiated. It describes how the combination of Chinese Communism and the unique cultural and linguistic heritage of the People’s Republic of China are driving Chinese cyber activity.

    The author, Lieutenant Colonel (Ret’d) William Hagestad II, is an internationally recognised subject matter expert on the Chinese People’s Liberation Army and Government Information Warfare. He advises international intelligence organisations and multi-national commercial enterprises with regard to their internal IT security governance and external security policies, making him the ideal person to write this book.

    21st Century Chinese Cyberwarfare is the first book to gather the salient information regarding the use of cyberwarfare doctrine by the People’s Republic of China, highlighting the increasing threat it imposes to the western world and the fact that Chinese cyberwarfare is a clear and present danger that can no longer be ignored. The book should be read by many, from individuals through to governmental departments, with everyone finding benefit in it.

    William Hagestad II adds, “My intent with this book was to introduce my readers to the Chinese culture, history and language through the lens of the People’s Liberation Army (PLA) information security & cyber warfare initiatives as a basis for economic, political and military hegemony by the Chinese Communist Party.”

    Alan Calder, CEO of IT Governance comments, “This book provides a fascinating and comprehensive study of the evolution and current nature of the Chinese approach to war ‘by other means’, conducted in what the Chinese see as the fifth sphere of war: cyberspace. ‘Know your enemy’ is a good starting point for any defence strategist and this book is an outstanding contribution to a better understanding of cyber security challenges that should be read by information security professionals the world over.”

    21st Century Chinese Cyberwarfare can be purchased in local currency from the ITG website

    Related story

    NATO Drafting Cyber Warfare International Law Manual


    Feb 21 2012

    50 Top IT Project Management Challenges

    Category: Information Security,ISO 27kDISC @ 10:58 pm

    A summary of the challenges facing today’s IT project manager
    Discussions on project management forums highlight many of the challenges facing a project manager during the course of a project. Unclear requirements, scope creep and undefined roles are well-trodden issues that can derail a project. Other challenges are less obvious, often more subtle, but equally destructive.

    Facing up to the challenges
    This book offers a focused and concise summary of 50 challenges facing today’s IT project manager. The authors draw on years of practical experience (rather than classroom theory) to outline these challenges and offer useful tips and advice on how to deal with them.

    Challenge and response
    Readers of this book will be better equipped to respond to key project management challenges, including

    • Building the team – getting the right resources, matching skills/knowledge, defining roles and responsibilities.
    • Project scope – clarifying assumptions, avoiding ambiguity, getting the time/cost estimates right.
    • Politics – communicating with management and stakeholders, dealing with conflict, handling interference and micro-managing.
    • Risk awareness – identifying inside/outside influences, recognising inbound and outbound dependencies.
    • Time management – using the right planning tools, balancing work versus meetings.
    • Failure – handling the blame game, protecting the team, rescuing the project.

    This book condenses into a handy summary much of the information and advice that can be found in project management related books and discussion forums. It is an ideal reference for anyone involved in IT project management, from professional service organisations (PSO) and project management offices (PMO), through to active project managers and studying graduates.

    Buy this book and deliver your next project on time, on budget and to specification!

    About the authors

    Premanand Doraiswamy has over 14 years’ experience working in IT project management with Fortune 500 companies in various industries and is the author of IT Project Management – 30 Steps to Success, also published by IT Governance.

    Premi Shiv is a quality assurance specialist with 7 years’ experience in IT processes and management solutions. With an optimistic approach and organisational skills, she has carved a niche in quality assurance.


    Feb 13 2012

    What Is a Security Incident and How to handle one

    Category: Security IncidentDISC @ 2:13 pm

    A security incident is a computer, network, or paper based activity which results (or may result) in misuse, damage, denial of service, compromise of integrity, or loss of confidentiality of a network, computer, application, or data; and threats, misrepresentations of identity, or harassment of or by individuals using these resources.

    Examples of incidents may include but not limited to the followings:
    • Root-level attacks on networking infrastructure, critical systems, or large, multi-purpose or dedicated servers
    • Compromise of privileged accounts on computer systems
    • Denial-of-service attacks on networking infrastructure and critical systems
    • Attacks launched on others from within umn.edu
    • Compromise of individual user accounts or desktop (single-user) systems
    • Scans of University systems originating from the Internet
    • Spam and mail forgery that originates from, or is relayed through umn.edu
    • Viruses, Worms and Trojan Horses

    Computer Security Incident Handling Guide


    « Previous PageNext Page »