 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Governance, Risk, and Compliance &#187; ISSM</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-governance/tag/issm/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-governance</link>
	<description></description>
	<lastBuildDate>Mon, 20 May 2013 00:56:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Business Continuity and IT Availability &#8211; Part VIII</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-viii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-viii/#comments</comments>
		<pubDate>Tue, 26 Jul 2011 20:04:12 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Backup]]></category>
		<category><![CDATA[BCM]]></category>
		<category><![CDATA[BCP]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[DRP]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Service Management]]></category>
		<category><![CDATA[Information Technology Service Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[ITSM]]></category>
		<category><![CDATA[Service Delivery]]></category>
		<category><![CDATA[Service Disruption]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=987</guid>
		<description><![CDATA[Regardless of organizational formation -- corporation, partnership, co-operative, or agency -- management has a generally accepted duty to plan and enact strategies permitting the entity’s survival under less than idealistic conditions.]]></description>
				<content:encoded><![CDATA[<p>Directly, an entity’s DRP has a significant affect on the viability of IT and information security governance programs.  Indirectly, IT and information security governance programs may impact stakeholder assessed entity value.  Regardless of organizational formation &#8212; corporation, partnership, co-operative, or agency &#8212; management has a generally accepted duty to plan and enact strategies permitting the entity’s survival under less than idealistic conditions.  Literally, adequate <strong>business continuity management</strong> (BCM) requires securing assets that offset catastrophic events.  Therefore, management should ensure ‘best practices’ DRP is deployed within the IT and information security governance frameworks as well as visibly communicate commitment expectations for sustaining a sound and effective continuity program.</p>
<p>&#8220;<em>View Part I of the Business Continuity and IT Availability series <a href="http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-i/">here</a>&#8220;</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-viii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Continuity and IT Availability &#8211; Part VII</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-vii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-vii/#comments</comments>
		<pubDate>Fri, 22 Jul 2011 17:35:49 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Backup]]></category>
		<category><![CDATA[BCM]]></category>
		<category><![CDATA[BCP]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[DRP]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Service Management]]></category>
		<category><![CDATA[Information Technology Service Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[ITSM]]></category>
		<category><![CDATA[Service Delivery]]></category>
		<category><![CDATA[Service Disruption]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=985</guid>
		<description><![CDATA[Through establishment and deployment of an emergency management program, top-level personnel can send a clear message to everyone in the entity that business continuity and disaster recovery control responsibilities are taken seriously.]]></description>
				<content:encoded><![CDATA[<p>Through establishment and deployment of an emergency management program, top-level personnel can send a clear message to everyone in the entity that <a href="http://www.amazon.com/Auditing-Business-Continuity-Disaster-Recovery/dp/193513325X/">business continuity and disaster recovery control</a> responsibilities are taken seriously.  If properly institutionalized, lower-level personnel will endeavor to understand germane aspects of the entity’s continuity systems, and how they operate, as well as their own roles and responsibilities within the control program.</p>
<p>Within the <strong>confidentiality</strong>, <strong>integrity</strong>, and <strong>availability</strong> (C-I-A) triad; pertinent financial and non-financial information relating to external or internal events, as well as daily activities, should be identified, captured, and communicated properly and in a timely manner to decision makers.  When required, established entity communication channels should permit authorized information flows throughout the organizational structure, with all relevant internal and external data reliably conveyed to intended recipients.</p>
<p>&#8220;<em>View Part I of the Business Continuity and IT Availability series <a href="http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-i/">here</a>&#8220;</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-vii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Continuity and IT Availability &#8211; Part VI</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-vi/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-vi/#comments</comments>
		<pubDate>Tue, 19 Jul 2011 20:04:26 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Backup]]></category>
		<category><![CDATA[BCM]]></category>
		<category><![CDATA[BCP]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[DRP]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Service Management]]></category>
		<category><![CDATA[Information Technology Service Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[ITSM]]></category>
		<category><![CDATA[Service Delivery]]></category>
		<category><![CDATA[Service Disruption]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=983</guid>
		<description><![CDATA[From flood or fire to computer-virus or denial-of-service, disasters can affect information assets crucial to conducting business locally, regionally, and globally.]]></description>
				<content:encoded><![CDATA[<p>Considering the interconnectivity of national economies through computer networks, entities are more vulnerable than ever to the possibility of technical difficulties disrupting business at any point in the communication chain.  From flood or fire to computer-virus or denial-of-service, disasters can affect information assets crucial to conducting business locally, regionally, and globally.  </p>
<p>To enable beneficial IT and information security service delivery and support (as with all processes) appropriate objectives, goals, policies, procedures, standards and rules are required.  Specifically, utilizing standards for ITSM usually generates benefits the moment an entity decides to rely on a business continuity service provider.  For example, using a publicly available, generally accepted, standard as the basis for a SLA between the entity and disaster recovery service partners will normally generate fewer disputes and lower costs.</p>
<p>&#8220;<em>View Part I of the Business Continuity and IT Availability series <a href="http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-i/">here</a>&#8220;</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-vi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Continuity and IT Availability &#8211; Part V</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-v/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-v/#comments</comments>
		<pubDate>Fri, 15 Jul 2011 02:44:20 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Backup]]></category>
		<category><![CDATA[BCM]]></category>
		<category><![CDATA[BCP]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[DRP]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Service Management]]></category>
		<category><![CDATA[Information Technology Service Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[ITSM]]></category>
		<category><![CDATA[Service Delivery]]></category>
		<category><![CDATA[Service Disruption]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=981</guid>
		<description><![CDATA[When a business interruption occurs, restored information assets may affect operational effectiveness and efficiency.]]></description>
				<content:encoded><![CDATA[<p>Managerial concerns normally include: <strong>excessive business costs</strong>, <strong>forgone business opportunities</strong>, and <strong>potential revenue losses</strong>.  When a business interruption occurs, restored information assets may affect operational effectiveness and efficiency.  Potentially, the IT function’s costs could escalate beyond tolerable limits, while user departments experience a general productivity and/or critical resource loss disabling pursuing business opportunities as well as economical revenue generation.  Specifically, errors in data back-up, storage, maintenance, retention and restoration may interfere with fulfilling organizational continuity and availability objectives.  For example, many entities rely on available information to provide feedback on divisional and departmental performance.  Errors in restored information could reduce management’s ability to evaluate performance and take appropriate corrective action; thus diminishing program, system and process monitoring effectiveness.</p>
<p>&#8220;<em>View Part I of the Business Continuity and IT Availability series <a href="http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-i/">here</a>&#8220;</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-v/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Continuity and IT Availability &#8211; Part IV</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-iv/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-iv/#comments</comments>
		<pubDate>Tue, 12 Jul 2011 21:32:25 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Backup]]></category>
		<category><![CDATA[BCM]]></category>
		<category><![CDATA[BCP]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[DRP]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Service Management]]></category>
		<category><![CDATA[Information Technology Service Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[ITSM]]></category>
		<category><![CDATA[Service Delivery]]></category>
		<category><![CDATA[Service Disruption]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=979</guid>
		<description><![CDATA[Where accepted as a managerial responsibility, an adequate ISG program should have security professionals participating in system life cycle design, acquisition, testing, and maintenance phases to ensure business continuity as well as availability requirements are appropriately incorporated...]]></description>
				<content:encoded><![CDATA[<p>Where accepted as a managerial responsibility, an adequate ISG program should have security professionals participating in system life cycle design, acquisition, testing, and maintenance phases to ensure business continuity as well as availability requirements are appropriately incorporated, that selected contingency configuration items function as intended and that deployed service restoration features are not compromised during maintenance. </p>
<p>As synthesized sub-frameworks, Information Technology Service Management (<a href="http://www.itil-itsm-world.com/">ITSM</a>) and Information Security Service Management (<a href="http://media.govtech.net/HP_RC_08/Security_RC/ISSM_for_SLG.pdf">ISSM</a>) promote entity information technology and information security units actively identifying services customers need; then focusing on planning and delivering defined services to meet availability as well as continuity requirements. Internally and externally; IT and/or information security units should manage accepted <strong>service-level agreements</strong> (SLAs) to meet agreed-upon service restoration targets.</p>
<p>&#8220;<em>View Part I of the Business Continuity and IT Availability series <a href="http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-i/">here</a>&#8220;</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/business-continuity-and-it-availability-part-iv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Measuring Delivery Value &#8211; Part IV</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-iv/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-iv/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 18:25:27 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Continuous Process Improvement]]></category>
		<category><![CDATA[CPI]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Infrastructure Management]]></category>
		<category><![CDATA[Information Security Processes]]></category>
		<category><![CDATA[Information Security Service Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISIM]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[IT Security Infrastructure]]></category>
		<category><![CDATA[IT Security Services]]></category>
		<category><![CDATA[Key Performance Indicators]]></category>
		<category><![CDATA[KPI]]></category>
		<category><![CDATA[Performance Measurement]]></category>
		<category><![CDATA[Safeguarding Investments]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=136</guid>
		<description><![CDATA[Measurement techniques are the means for effective information security performance monitoring.]]></description>
				<content:encoded><![CDATA[<p>Performance measurement is a control activity. Measurement techniques are the means for effective information security performance monitoring. &#8220;Selective measurement utility is realized when a critical few indicators permit accurate and timely information for decision-making and, by extension, appropriate <a href="http://www.theiia.org/bookstore/product/it-auditing-information-assets-protection-iap-1276.cfm">information assets protection</a>.&#8221; KPIs provide the critical measuring technique for aligned objectives and goals. Adequate KPIs permit comparative analysis for assessing resource deployment and utilization success. When processes are evaluated within the pre-established context, KPIs enable rapid resource mobilization, substitution and/or elimination for organizational objectives fulfillment.</p>
<p><em>&#8220;View Part I of the Measuring Delivery Value series </em><a href="http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-i//"><em>here</em></a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-iv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Measuring Delivery Value &#8211; Part III</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-iii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-iii/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 18:41:22 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Continuous Process Improvement]]></category>
		<category><![CDATA[CPI]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Infrastructure Management]]></category>
		<category><![CDATA[Information Security Processes]]></category>
		<category><![CDATA[Information Security Service Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISIM]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[IT Security Infrastructure]]></category>
		<category><![CDATA[IT Security Services]]></category>
		<category><![CDATA[Performance Measurement]]></category>
		<category><![CDATA[Safeguarding Investments]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=131</guid>
		<description><![CDATA[...an adequate KPI enables determination of the degree of change from the current state to future expectations.]]></description>
				<content:encoded><![CDATA[<p>Information security <a href="http://www.pleier.com/itadsweb.htm">service management</a> can include financial and non-financial indicators to enable performance assessments. However, selected indicators must represent a mathematically measurable quality. An adopted KPI should have an established target, associated with a completion date and a path for improvement. Furthermore, an adequate KPI enables determination of the degree of change from the current state to future expectations. For instance, an information security goal might address access privileges. Consequently, considering the current state requires comparison to accepted standards for performance measurement, the &#8220;time to grant access privileges&#8221; KPI would specify whether the measurement duration is in minutes, hours or days. Reflecting the established time basis, a target for the KPI can be derived. Therefore, &#8220;reduce time to grant access privileges by four percent per year&#8221; communicates a clear target that employees should understand and undertake specific actions to accomplish. </p>
<p>One of the managerial challenges for process-driven entities is integrating &#8216;leading indicators&#8217; into KPIs. Similar to leading economic indicators, information security leading KPIs enable swift conditional <a href="http://www.pleier.com/infosecmgmt.htm">service delivery</a> responses to &#8216;code red&#8217; impact alerts. If leading indicators are properly implemented, management can preemptively adjust a process (or processes) before the expiration date on achieving an expected outcome.</p>
<p><em>&#8220;View Part I of the Measuring Delivery Value series </em><a href="http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-i//"><em>here</em></a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-iii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Measuring Delivery Value &#8211; Part II</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-ii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-ii/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 19:42:38 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Continuous Process Improvement]]></category>
		<category><![CDATA[CPI]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Infrastructure Management]]></category>
		<category><![CDATA[Information Security Processes]]></category>
		<category><![CDATA[Information Security Service Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISIM]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[IT Security Infrastructure]]></category>
		<category><![CDATA[IT Security Services]]></category>
		<category><![CDATA[Safeguarding Investments]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=125</guid>
		<description><![CDATA[...goals must be established with appropriate performance indicators for status assessments.]]></description>
				<content:encoded><![CDATA[<p>Procedurally, once information security management has analyzed the entity-centric mission, identified stakeholders, and defined objectives; goals must be established with appropriate performance indicators for status assessments. &#8220;Practical information security service delivery and support utilization requires identification of a critical few measurement indicators in each of the relevant measurement domains that align <a href="http://diy.craigspress.com/BookStore/BookStoreBookDetails.aspx?bookid=48453">safeguarding initiatives</a> to targeted processes and activities. At the detail-level, these few critical measurements represent key performance indicators [(KPIs)] tailored to gauge objective achievement elements. To effectively drive performance alignment, entities should utilize expected outcomes to enable multiple measurements identification so the positive impact safeguarding investments contribute are visible.&#8221; </p>
<p>KPIs are utilized to measure achievements through comparative analyses. Information accuracy and consistency are rudimentary to measurement reliance. If KPIs are going to reliably convey activity status, management must accurately define and consistently <a href="http://www.pleier.com/itasecgovweb.htm">measure expectations</a>. That is, activity calculation inputs must be understood and accepted by those accountable for expected performance until revision notification.</p>
<p><em>&#8220;View Part I of the Measuring Delivery Value series </em><a href="http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-i//"><em>here</em></a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Measuring Delivery Value &#8211; Part I</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-i/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-i/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 17:56:48 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Continuous Process Improvement]]></category>
		<category><![CDATA[CPI]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Infrastructure Management]]></category>
		<category><![CDATA[Information Security Processes]]></category>
		<category><![CDATA[Information Security Service Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISIM]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[IT Security Infrastructure]]></category>
		<category><![CDATA[IT Security Services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=119</guid>
		<description><![CDATA[...information security service level management should be considered quality of service administration permitting demonstrable process improvement contributions.]]></description>
				<content:encoded><![CDATA[<p>Considering adamant demands for continuous process improvements, focus on overall information protection and delivery value in terms of enabled <a href="http://www.pleier.com/itadsweb.htm">services</a> has become a managerial necessity. Information Security Service Management is a set of processes enabling and potentially optimizing IT security services for an entity in order to satisfy business requirements, while simultaneously providing strategic and tactical IT security infrastructure management. Consequently, information security service level management should be considered quality of service administration permitting demonstrable process improvement contributions. Measuring, monitoring and reporting on information security processes assist in ensuring organizational objectives are achieved.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/measuring-delivery-value-part-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Measuring Performance &#8211; Part IV</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/measuring-performance-part-iv/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/measuring-performance-part-iv/#comments</comments>
		<pubDate>Tue, 14 Apr 2009 01:08:28 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[CE]]></category>
		<category><![CDATA[Control Environment]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[ISSM]]></category>
		<category><![CDATA[IT Security Program]]></category>
		<category><![CDATA[ITSM]]></category>
		<category><![CDATA[Key Performance Indicators]]></category>
		<category><![CDATA[KPI]]></category>
		<category><![CDATA[Safeguarding Investments]]></category>
		<category><![CDATA[Service Delivery and Support]]></category>
		<category><![CDATA[Service Level Agreement]]></category>
		<category><![CDATA[Service Management]]></category>
		<category><![CDATA[SLA]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=116</guid>
		<description><![CDATA[Individually, measurement techniques are the means for effective IT security performance monitoring.]]></description>
				<content:encoded><![CDATA[<p><span style="font-size: 10pt;font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&amp;quot">Selective measurement utility is realized when a critical few indicators permit accurate and timely information for decision-making and, by extension, appropriate information assets protection. Individually, measurement techniques are the means for effective IT security <a href="http://www.isaca.org/Content/ContentGroups/Research1/Deliverables/Information_Security_Governance_Guidance_for_Boards_of_Directors_and_Executive_Management_2nd_Editio.htm">performance monitoring</a>. Collectively, IT security services financial management and maturity modeling are powerful high-level tools for assessing the achievement of objectives and goals.</span></p>
<p><em>&#8220;View Part I of the Measuring Performance series </em><a href="http://itknowledgeexchange.techtarget.com/it-governance/measuring-performance-part-i//"><em>here</em></a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/measuring-performance-part-iv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
