ISO 17799 Information Aggregator

Introduction to Information Security Awareness

Posted: June 21st, 2010 | Author: | Filed under: YouTUBE Videos | Tags: , , , , , , , , , , , | No Comments »

Cybert threats have learned that the easiest way to compromise your organization is not by targeting your technology but by targeting your employees. The human has become the weakest link. HoneyTech is an information security consultancy that specializes in security awareness and training. We have worked with over twenty countries around the world. Our comprehensive awareness solutions have secured organizations from 90000 employees to just 90. To learn more how we can help you, please contact us at www.honeytech.com info@honeytech.com

http://www.youtube.com/v/uebzVb_g1Lw?f=videos&app=youtube_gdata

Read the original post: Introduction to Information Security Awareness


Understanding EX0-101 Certification Exam

Posted: June 20th, 2010 | Author: | Filed under: Uncategorized | Tags: , , , , , , , | No Comments »

The test Institute for Information Science which is coined as EXIN is an self-governing IT exam provider. The chief objective of this organization is to get better the quality of IT industry by improving the quality of IT professional so that to satisfy the IT users. This organization helps the IT professional to withstand themselves in ever rising competition in IT industry.

EXIN is a worldwide independent IT test provider which offers numeral of certifications. This organization conducts exam over 125 countries and it is conducted in 15 different languages. This is mostly to help IT professionals to write exams in their own language so that they can take the test in a simple manner. This institute provides diversity of courses and so that everybody can decide the exams that suites their profession. This institute conducts tests in six continents based on the job roles necessary by the workers. All EXIN exams are held based on the globally accepted standards like ISO/IEC 20000, ISO/IEC 27000, ITIL, MOF, ASL, BiSL, TMAP and ASP. Additionally to the exam the EXIN conducts excellence programs as IT service management based on the ISO/IEC 20000 and also this institute conducts in sequence security program based on ISO/IEC 27002.

This institute conducts exams like EX0-101 which are obliging to make IT professional to put them in an outstanding position in IT industry. EXIN offers an international qualification program and also it offers a complete pack of IT certification program which contains exam development, accreditation and registration, test and certification. EXIN exam assists IT experts to increase their skills, to inform their knowledge, to establish their skill in the organization and also increases the excellence in their profession. The certification provided by this institute also assists IT professional to boost their presentation. Overall this certification assists IT professional to withstand in a good position in the bloodthirsty IT field.

Retrieved from “http://www.articlesbase.com/information-technology-articles/understanding-ex0101-certification-exam-1508292.html”

Original post: Understanding EX0-101 Certification Exam


ISO/IEC 27000 Information Security Standards Family Adopts a New …

Posted: June 20th, 2010 | Author: | Filed under: Uncategorized | Tags: , , , , , , , , , | No Comments »

ISO (the International Organization for Standardization) and IEC (the International Electrical Committee) released ISO/IEC 17799 in 2000 and revised in 2005. Apart from the name , ISO/IEC 27002:2005 is identical to ISO 17799:2005. …

Read the rest here: ISO/IEC 27000 Information Security Standards Family Adopts a New …


Top 10 Information Systems Security Controls in the Enterprise

Posted: June 20th, 2010 | Author: | Filed under: Uncategorized | Tags: , , , , , , , , , , , , | No Comments »

The modern Enterprise IT Infrastructure as we know it today has evolved over the years, from the huge computers in the mid 1940s, which could not even do what our small calculators can do today, to the years of mainframes. We now have high processor computers with lots of storage space and high speeds that are easily affordable. We have seen a shift of focus from centralized to decentralized, distributed, network computing within enterprises. All these developments have been great, as they have eased the way we do business, but also brought myriad of enterprise security issues.

In this article we look at the top 10 enterprise security controls that we could deploy to reduce on the effect of known enterprise infrastructure security issues.

1. Take a holistic approach to security

Successful enterprise security requires good planning and a holistic security strategy that considers everything in the organizations, from business processes to the people, on an ongoing basis. Many at times enterprises consider costly technical solutions, as a reaction to security breaches.

2. Develop an Enterprise security program / policy

Organizations need to develop security programs that outline the Roles, policy, procedures, standards and guidelines for the Enterprise security.

Roles: Outline who is responsible for what e.g. Chief Information security officer (ISO) could be s responsible for ensuring a good security posture for the organization.

Policies: These are general organization wide statements that set out the mandatory requirements to ensure a minimum security level. Examples include: Acceptable E-mail Use Policy, Internet use policy, Mobile devices use policy etc…

Standards: these are derived from policies, laying out specific steps or processes required to meet a certain requirement. For example a requirement that all email communication be encrypted.

3. Manage Risk – On a continuous basis

Risk management is the process of identifying risk, assessing risk, and taking steps to reduce risk to an acceptable level. This involves identifying the assets in the organization that you need to secure; these could include human resources, technology, trade secrets, patents, copyrights etc… Then identify all possible risks that could affect the availability, confidentiality and integrity of these assets. Management can then decide what to do with the identified risks; risks can either be mitigated or transferred to a third party like an insurance company.

4. Refine Business Processes: Adopt Industry best Practices

Beyond the need to manage Enterprise IT technology, is the need to establish and employ best practices and processes to optimize IT services. A number of internationally recognized frameworks have been developed already to describe effective ICT infrastructure management processes. Hence there is no need to re-invent the wheel.

Examples include:
COBIT - Control Objectives for Information and related Technology {1},
ITIL - The Information Technology Infrastructure Library {2}
and ISO 27001 {3}

5. Streamline physical / environmental security

Physical and environmental security is vital in protection of information assets and ICT Infrastructure in the Enterprise. Physical security should look at issue like, monitoring and detection e.g. security guards, alarms, CCTV. Access control and deterrent solutions e.g locks, fencing, lighting, mantraps, Biometrics etc. Environmental control and design, server room temperature, humidity, air conditioning, static electricity, fire suppression and detection, Power generation and backup, all these should be well streamlined.

6. Deploy content filtering / inspection solutions.

As content, (email, internet traffic etc…) moves in and out of the enterprise, there is need for it to be managed well to avoid any security breaches and attacks. Controls could include:

- Web filters to enforce organizational Internet usage policies through content filtering, application blocking, and best-of-breed spyware protection.

- Spam filters / Firewalls to protect your email server from spam, virus, spoofing, phishing and spyware attacks.

- Unified Threat management solutions(UTM): Several organization choose to deploy UTM solutions that offer industry leading functionalities within one package including Intrusion Prevention System; Antivirus with Antispam; Web Filtering; Antispam; Firewall; SSL – VPN; Traffic Shaping and many more.

7. Manage the inside of the Corporate Network

We have already seen that there are increased security breaches that come from within the enterprise; therefore it’s vital to manage the inside of the enterprise network very well. Some of the steps we could take include the following:

- Taking an inventory of all authorized and unauthorized software and devices on the network.
- Maintenance, Monitoring, and Analysis of Audit Logs
- Continuous Vulnerability Assessment, patch management and Remediation
- Limitation and Control of Network Ports, Protocols, and Services

8. Have an Identity and Rights Management System

Identity management is very vital and important to avoid user rights violation and excessive rights issue. Put in place procedures, guideline and a system for Identity management, which involves creation of users, change of user rights, removal of rights, resetting lost user password. This also calls for Controlled Use of Administrative Privileges. Is access in the Enterprise based on a need to know basis? For example should everyone in the organization have access to the payroll database?!

9. Put emphasis on Data Loss Prevention (DLP).

Data loss prevention puts into consideration the security of data, both in motion and static. With the advent of portable devices and memory sticks that have lots of storage space, it very easy for someone to copy lots of corporate data on a removable media in just a matter of seconds. I have heard of stories of disgruntled employees selling clients databases to the competition. Data loss prevention (DLP) encompasses the tools that prevent accidental data leakage, including device and port control, encryption (both hard-drive and removable media encryption).

Also how does your organization handle hard disks that have sensitive information and need disposing off? How about paper documents? I bet one could get lots of information by just dumpster diving into corporate trash bins (am told some investigative journalists use this method to “snoop”). There is no excuse for organization not to shred sensitive paper documents, given all the shredders available on the market; some can even shred plastic and CD media.

10. Don’t go it alone

Securing information assets is becoming more vital every day; unfortunately many organizations do not consider it important until a breach has actually happened.

You can imagine the direct cost of not being proactive as far as information security is concerned, which could include, the cost to recover data lost or altered during an incident, cost to notify customers of breaches, fines for non-compliance and indirect costs e.g., lost customers, lost productivity, time spent investigating/resolving breaches and hoaxes, and so many. Therefore it’s crucial to seek for external assistance from an external firm or consultant if need be, to assist in areas like:

- Carrying out an IT audit and Penetration Tests a.k.a “Ethical hacking” on your own infrastructure.
- Assisting with Information security awareness training for your staff etc…

It’s important to note that securing information assets in an enterprise is not just an event, but is a continued process that requires an ongoing effort and support of the top management, this is because the threats to information systems continues to evolve and change daily.

References:

1 itgovernance
2 itlibrary.org
3 http://www.27000.org

About the Author

Mr. Thomas Bbosa – CISSP, is an Information Systems security Consultant and Managing Partner with BitWork Technologies Ltd – http://www.bitworktech.com, an IT firm based in Kampala, Uganda. He is a certified Information Systems Security Professional (CISSP), with over 10 years Experience in the IT industry. He has been involved in various roles of IT infrastructure management and support, Information systems Security management & solutions deployment.

Article Source:

http://EzineArticles.com/?expert=Thomas_Bbosa

Read the original post: Top 10 Information Systems Security Controls in the Enterprise


Getting Started with ISO/IEC 27000

Posted: June 20th, 2010 | Author: | Filed under: Uncategorized | Tags: , , , , , , , , , , | No Comments »

The ISO/IEC 27000 series includes information security standards published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The ISO 27000 series comprises of a family of information security standards that include the ISO 27001 and the ISO 27002 among others.

Why is the ISO 27000 such an important standard in the world of information security? The ISO 27000 series provides best practice recommendations on information security management, risks and controls within the context of an overall Information Security Management System (ISMS). It is applicable to organizations of all types, across industries, and sizes.

The ISMS concept integrates continuous feedback and improvement activities summarized by a €Plan-Do-Check-Act (PDCA)€ approach.

In this executive brief, we focus on the two standards that influence information security initiatives worldwide €“ the ISO 27001 and ISO 27002. The ISO 27001 International Standard is about requirements related to security techniques for information technology and information security management systems.

The ISO 27001 International Standard was developed to provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an ISMS.

ISO/IEC 27002 provides best practice recommendations on information security management for use by those who are responsible for initiating, implementing or maintaining an ISMS.

Your organization may be impacted by regulations such as the Health Insurance Portability and Accountability Act (HIPAA) and possibly other regulations such as the Payment Card Industry€™s Data Security Standard (PCI€™s DSS) or U.S. State requirements. An important reference and an excellent framework in the world of information security is the ISO 27001 standard. The ISO 27001 is one of several standards developed by the International Standards Organization (ISO) in the area of information security.

Retrieved from “http://www.articlesbase.com/management-articles/getting-started-with-isoiec-27000-918882.html”

More: Getting Started with ISO/IEC 27000


Low Cost Data Entry and Data Processing Services

Posted: June 17th, 2010 | Author: | Filed under: Uncategorized | Tags: , , , , , , , | No Comments »

This is an era where specialized jobs have become the norm of the day. Data entry is one of these jobs, which includes providing and recording all kinds of data for a specific purpose. There are companies as well as individuals who provide various kinds of data entry services. Apart from data entry, they also do data processing.This processing may be needed for successful insurance claims processing and the like. If you are thinking about the cost, you need not worry much as you can take advantage of the vast outsourcing market.

The outsourcing market has many companies and many individual professionals who work as data entry specialists and can also provide data processing services. You can choose a vendor who addresses your particular requirements and promises to deliver on time. As it is oft repeated by various market analysts and others, outsourcing saves your time and money.

There are many people and organizations that do these data entry jobs at a reasonable rate. So, these services will not pinch your pocket too much. At the same time, you and your employees can concentrate on more important jobs, leaving the mundane data entry jobs to be done by specialists who know how to do the job in an efficient manner. In case you want to forward your medical insurance claims and do not have the time to fill up the numeric details of billing and coding, you need not fret and fume for data entry service providers are there to help you.

These service providers will diligently go through your records and fill in all the necessary details. It is important to keep an eye on such detail. Otherwise, there will be a risk of your claims getting rejected. This is a fact that has been witnessed many times, especially in cases of medical claims processing.

People often think that anything that is low cost is bound to be shoddy. It is not like that with cost effective data entry and data processing services. In fact, outsourcing guarantees you best services at a lower cost than what you would have spent to get the job done by in-house employees. This is the beauty of outsourcing where you need not compromise on efficiency or the end result, and yet save some precious dollars and time.

Low cost data entry and data processing services also take care of your efficiency. You virtually bring a more systematic mode of work without spending a fortune or wasting your own time. It is not always possible for everybody to learn everything. That is why these specialists who have the requisite technical knowledge can come handy.

The success of any business lies in the fact that it benefits all the participants. By hiring low cost data entry service providers, you as the client and the company – both can reap the advantages.

Rely Services is one such company that has many specialists on its pay role, who can get your data entry and data processing jobs completed in quick time.

Rely Services, Established in 1997, with over 450 experienced staff working in 3 shifts for 24 x 7 x 365 days, is a strong customer centric organization following ISO 9000, 17799 & HIPPA guidelines. It has its headquarters in Illinois – Hoffman Estates and operation units in Michigan & Ohio and is on the verge of expanding its presence in more states.

Article Source:

http://EzineArticles.com/?expert=Peter_McRoy

See original here: Low Cost Data Entry and Data Processing Services