December 27, 2012 1:31 AM
Posted by: Robert Davis
Accountability,
Acquire and Implement,
Adaptive Systems,
Asset Management,
Availability Management,
COBIT,
COBIT Domains,
Control Environment,
Control Objectives for Information and related Technology,
Deliver and Support,
Due Diligence,
Fiduciary Responsibility,
Framework,
Information Assets Protection,
Information Security Governance,
Information Security Management,
ISG,
Key Performance Indicators,
Monitor and Evaluate,
Performance Measurement,
Plan and Organize,
Risk Management,
Security Frameworks,
Strategic Alignment,
Value Delivery1.1 Control Environment
“…culture determines the behaviour of people in an organisation and should, therefore, be used to influence the behaviour of people with regard to information security.” – Kerry-Lynn Thomson and Rossouw von...
December 22, 2012 1:43 AM
Posted by: Robert Davis
Accountability,
Acquire and Implement,
Asset Management,
Availability Management,
COBIT Domains,
Control Objectives for Information and related Technology,
Deliver and Support,
Due Diligence,
Fiduciary Responsibility,
Framework,
Information Assets Protection,
Information Security Governance,
Information Security Management,
ISG,
Key Performance Indicators,
Monitor and Evaluate,
Plan and Organize,
Risk Management,
Value DeliveryUsually, a formal ISG program is required to promote information assets safeguarding. ISG programs should ensure the Control Objectives for Information and related Technology (COBIT) framework confidentiality, integrity, availability, compliance, and reliability information criteria are not...
December 20, 2012 2:52 AM
Posted by: Robert Davis
Accountability,
Acquire and Implement,
Asset Management,
Availability Management,
COBIT Domains,
Control Objectives for Information and related Technology,
Deliver and Support,
Due Diligence,
Fiduciary Responsibility,
Framework,
Information Assets Protection,
Information Security Governance,
Information Security Management,
ISG,
Key Performance Indicators,
Monitor and Evaluate,
Plan and Organize,
Risk Management,
Value DeliveryAcquisitions and implementations are necessary for adequate information security. To realize the information security strategy, information security solutions need to be identified, developed or acquired, as well as implemented and integrated into business and IT processes seamlessly. During an...
December 15, 2012 12:05 AM
Posted by: Robert Davis
Accountability,
Acquire and Implement,
Asset Management,
Availability Management,
COBIT Domains,
Control Objectives for Information and related Technology,
Deliver and Support,
Due Diligence,
Fiduciary Responsibility,
Framework,
Information Assets Protection,
Information Security Governance,
Information Security Management,
ISG,
Key Performance Indicators,
Monitor and Evaluate,
Plan and Organize,
Risk Management,
Security Frameworks,
Value DeliveryInstituting and/or sustaining ISG requires comprehensive planning and organizing; robust acquisitions and implementations; effective delivery and support; as well as continuous monitoring and evaluation to address the myriad of managerial, operational, and technical issues that can thwart...
December 13, 2012 1:52 AM
Posted by: Robert Davis
Accountability,
Acquire and Implement,
Asset Management,
Availability Management,
COBIT Domains,
Continuity Management,
Control Objectives for Information and related Technology,
Deliver and Support,
Due Diligence,
Fiduciary Responsibility,
Framework,
Information Assets Protection,
Information Security Governance,
Information Security Management,
ISG,
Key Performance Indicators,
Monitor and Evaluate,
Performance Measurement,
Plan and Organize,
Risk Management,
Security Frameworks,
Strategic Alignment,
Value DeliveryChapter 1: Information Security Governance
“The information possessed by an organization is among its most valuable assets and is critical to its success. The Board of Directors, which is ultimately accountable for the organization’s success, is therefore...
December 8, 2012 1:34 AM
Posted by: Robert Davis
Access Controls,
Availability Management,
Configuration Management,
Continuous Monitoring,
Control Techniques,
Distributed Platforms,
Exception Reporting Systems,
Information Assets Protection,
IT Security Infrastructure,
Logical Security,
Management Information Systems,
Risk ManagementNetwork-based intrusion detection captures traffic and performs analyses to identify notable events. If placed at the front-end IT perimeter, the properly configured network-based IDS will detect all externally initiated attack attempts, even where the firewall subsequently permits...
December 5, 2012 11:32 PM
Posted by: Robert Davis
Access Controls,
Availability Management,
Continuous Monitoring,
Control Techniques,
Distributed Platforms,
Exception Reporting Systems,
Hackers,
Information Assets Protection,
IT Security Infrastructure,
Logical Security,
Management Information Systems,
Risk Management
December 1, 2012 12:09 AM
Posted by: Robert Davis
Access Controls,
Availability Management,
Continuous Monitoring,
Control Techniques,
Distributed Platforms,
Exception Reporting Systems,
Hackers,
Information Assets Protection,
IT Security Infrastructure,
IT Security Services,
Logical Security,
Management Information Systems,
Risk ManagementAs suggested in the aforementioned paragraph, depending on the...