 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Answers &#187; Security Program Management</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/tag/security/security-program-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers</link>
	<description></description>
	<lastBuildDate>Thu, 23 May 2013 22:05:52 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Information Security Awareness</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/information-security-awareness/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/information-security-awareness/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 18:43:26 +0000</pubDate>
		<dc:creator>Toyz</dc:creator>
				<category><![CDATA[Information security]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[We are in the early stages of creating an Information Security program for our new company.  I would like to email monthly security tips, tidbits, etc  for Security Awareness to all employees.  Have you seen anything &#8220;catchy&#8221;, grab your attention type email subject lines and/or icons, so we can catch people&#8217;s attention to these monthly [...]]]></description>
				<content:encoded><![CDATA[<p>We are in the early stages of creating an Information Security program for our new company.  I would like to email monthly security tips, tidbits, etc  for Security Awareness to all employees.  Have you seen anything &#8220;catchy&#8221;, grab your attention type email subject lines and/or icons, so we can catch people&#8217;s attention to these monthly topics?</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/information-security-awareness/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>How Many Information Security Policies Do I Need?</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/how-many-information-security-policies-do-i-need/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/how-many-information-security-policies-do-i-need/#comments</comments>
		<pubDate>Mon, 03 Jan 2011 03:49:18 +0000</pubDate>
		<dc:creator>Vper</dc:creator>
				<category><![CDATA[ISO 17799]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Network Security Policies]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SAS 70 Type II audit compliance]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I need some advice from other security experts. I was recently hired to work for a small company where our data and infrastructure is at a managed hosting facility. The hosting service has a SAS 70 that is regularly audited.  My company in the past relied – almost solely – on the managed service security [...]]]></description>
				<content:encoded><![CDATA[<p>I need some advice from other security experts. I was<br />
recently hired to work for a small company where our data and infrastructure is<br />
at a managed hosting facility. The hosting service has a SAS 70 that is<br />
regularly audited.  My company in the past relied – almost solely – on the<br />
managed service security plans and controls. However, I am wondering if that is<br />
truly enough or if we need to develop our own security plans and policies for<br />
that infrastructure and data or continually reference the hosting company’s<br />
documents?<br/><br/></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/how-many-information-security-policies-do-i-need/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft&#8217;s Defender management and monitoring</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/microsofts-defender-management-and-monitoring/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/microsofts-defender-management-and-monitoring/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 13:31:22 +0000</pubDate>
		<dc:creator>NewnanIT</dc:creator>
				<category><![CDATA[Domain]]></category>
		<category><![CDATA[Domain Administration]]></category>
		<category><![CDATA[Security in 2010]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Windows Application]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Can Microsoft’s Defender be managed centrally from a server? Can I review logs across the domain? Is this possible or is there a similar corporate offering from Microsoft?]]></description>
				<content:encoded><![CDATA[<p>Can Microsoft’s Defender be managed centrally from a server? Can I review logs across the domain? Is this possible or is there a similar corporate offering from Microsoft?</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/microsofts-defender-management-and-monitoring/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Open IT Forum: What security-related lessons have you learned?</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-security-related-lessons-have-you-learned/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-security-related-lessons-have-you-learned/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 14:27:50 +0000</pubDate>
		<dc:creator>MelanieYarbrough</dc:creator>
				<category><![CDATA[Open IT Forum]]></category>
		<category><![CDATA[Security in 2010]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[What is the hardest or most costly (whether it be time, money or pride) lesson you or your company has learned regarding security? We want to hear your security-related stories, concerns and blunders in the discussion area. The most entertaining or insightful stories have 200 knowledge points waiting for them.]]></description>
				<content:encoded><![CDATA[<p><img src="http://http.cdnlayer.com/itke/blogs.dir/24/files/2009/09/forum.jpg" style="float: right; margin: 10px;" width="75" height="50" />What is the hardest or most costly (whether it be time, money or pride) lesson you or your company has learned regarding security? </p>
<p>We want to hear your security-related stories, concerns and blunders in the discussion area. The most entertaining or insightful stories have 200 knowledge points waiting for them.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/open-it-forum-what-security-related-lessons-have-you-learned/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>What do you foresee as your biggest security concerns in the upcoming year?</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/what-do-you-foresee-as-your-biggest-security-concerns-in-the-upcoming-year/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/what-do-you-foresee-as-your-biggest-security-concerns-in-the-upcoming-year/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 16:43:07 +0000</pubDate>
		<dc:creator>JennyMack</dc:creator>
				<category><![CDATA[Open IT Forum]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Metrics]]></category>
		<category><![CDATA[Security Planning]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[As you begin planning for next year&#8217;s department spending and resource allocation, what do you foresee as your biggest areas of security concern in the upcoming year? Do you think particular areas will require special attention or resources?]]></description>
				<content:encoded><![CDATA[<p>As you begin planning for next year&#8217;s department spending and resource allocation, what do you foresee as your biggest areas of security concern in the upcoming year? Do you think particular areas will require special attention or resources?</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/what-do-you-foresee-as-your-biggest-security-concerns-in-the-upcoming-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT Security</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/it-security-2/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/it-security-2/#comments</comments>
		<pubDate>Mon, 16 Jun 2008 14:47:43 +0000</pubDate>
		<dc:creator>Davemd</dc:creator>
				<category><![CDATA[Application security]]></category>
		<category><![CDATA[Career development]]></category>
		<category><![CDATA[Career in Information Security]]></category>
		<category><![CDATA[Careers in networking]]></category>
		<category><![CDATA[Certification and specializations]]></category>
		<category><![CDATA[Certifications]]></category>
		<category><![CDATA[CISSP]]></category>
		<category><![CDATA[CISSP certification]]></category>
		<category><![CDATA[Desktop security]]></category>
		<category><![CDATA[IT careers]]></category>
		<category><![CDATA[MCSA]]></category>
		<category><![CDATA[MCSE]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Networking certifications]]></category>
		<category><![CDATA[Platform Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security certifications]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Securitychannel]]></category>
		<category><![CDATA[Staffing]]></category>
		<category><![CDATA[Windows Security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[With all the talk about security certifications and working in IT security being hot right now and in the future, I was wondering if it would make more sense to try and get the Security + certification before trying to get another IT certification such as the MCSA (Microsoft Certified Systems Administrator)? I’ve heard that [...]]]></description>
				<content:encoded><![CDATA[<p>With all the talk about security certifications and working in IT security being hot right now and in the future, I was wondering if it would make more sense to try and get the Security + certification before trying to get another IT certification such as the MCSA (Microsoft Certified Systems Administrator)? I’ve heard that most certifications (other than security) don’t mean that much anymore to employers, and that skills now beat having certifications. Also, I noticed for many other security certifications such as the CISSP, the requirements to take the test are very strict, in that you need to have 5 years of experience working in security. How does one get that experience if they’ve never specifically worked in security? What if someone was more of an IT Generalist, or IT jack-of-all-trades where they worked? I think I want to head in the security direction, but how do I do it? For the past couple of years, I’ve worked for a small firm where I am the only one that does all the IT stuff, and security was really never an everyday issue. My job title probably ties more closely to an IT Administrator or Systems Administrator. I appreciate any help and feedback. Thanks very much.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/it-security-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SAP Security outside in</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/sap-security-outside-in/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/sap-security-outside-in/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 15:16:15 +0000</pubDate>
		<dc:creator>1112gene</dc:creator>
				<category><![CDATA[SAP]]></category>
		<category><![CDATA[SAP security]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[VB]]></category>
		<category><![CDATA[Visual Basic]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Question, I came to this company 1yr ago and noticed immediately they had not implemented Security!!! SAP_ALL for everyone in Production!!! So as my second BIG project I took on, Security. In building the profiles for these people I came across 2 problems which are holding me from rolling out these profiles I built, which [...]]]></description>
				<content:encoded><![CDATA[<p>Question,<br />
I came to this company 1yr ago and noticed immediately they had not implemented Security!!! SAP_ALL for everyone in Production!!!<br />
So as my second BIG project I took on, Security. In building the profiles for these people I came across 2 problems which are holding me from rolling out these profiles I built, which are based on the same problem, an outside system coming into SAP.<br />
Since everyone had SAP_ALL or NEW we had no problems but restricting the Authority has shut down the operation and accessibility of these 2 outside systems which are very necessary. </p>
<p>1st problem and biggest is we have a VB frontend to SAP for easy order taking for Custom Service Dept.<br />
I found out the design/programmer used a VB call into SAP via a VB BAPI that will allow MS into SAP.<br />
He did not setup an RFC via SM59 or a Trusted RFC, and has no call for Call Function: for Authority_Check_RFC in the VB program, which prevents the Login and Security check being passed allowing access!</p>
<p>I told them this would not work with out the Call Function: from the VB program as a start and if it doesn’t work we need to do the RFC via SM59 or STV1. </p>
<p>It’s gotten personal and they think I have not setup S_RFC with proper Authorization but in order to do that you need Object Group AAAB, take S_RFC and throw out the rest, but I still don’t see that as a solution w/o the Call Function in the VB program!<br />
What say you?</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/sap-security-outside-in/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Selecting an area within security to start</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/selecting-an-area-within-security-to-start/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/selecting-an-area-within-security-to-start/#comments</comments>
		<pubDate>Sun, 24 Jun 2007 16:06:15 +0000</pubDate>
		<dc:creator>Secmax</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Career development]]></category>
		<category><![CDATA[CCNA]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[Certifications]]></category>
		<category><![CDATA[CISSP]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[configuration]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[Current threats]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Digital certificates]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Intrusion management]]></category>
		<category><![CDATA[MCSE]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[PEN testing]]></category>
		<category><![CDATA[Platform Security]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[SSL/TLS]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<category><![CDATA[Web security]]></category>
		<category><![CDATA[Wireless]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Hi, I&#8217;m studying for an MSc in Information Security from Royal Holloway University of London, I have a B.Engg. degree in computers and a PG Diploma in Networking and Communication as well as the CCSA and CCNA. I&#8217;m also studying for the CISSP. Now, with all these qualifications, could you please tell me which would [...]]]></description>
				<content:encoded><![CDATA[<p>Hi,<br />
I&#8217;m studying for an MSc in Information Security from Royal Holloway University of London, I have a B.Engg. degree in computers and a PG Diploma in Networking and Communication as well as the CCSA and CCNA. I&#8217;m also studying for the CISSP.</p>
<p>Now, with all these qualifications, could you please tell me which would be the best position for me to apply for in order to get a start, and if I try that position what would my options be when I gain some experience. </p>
<p>Thank you!!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/selecting-an-area-within-security-to-start/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Procedures for a new area.</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/procedures-for-a-new-area/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/procedures-for-a-new-area/#comments</comments>
		<pubDate>Wed, 23 May 2007 22:13:31 +0000</pubDate>
		<dc:creator>Millan</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[backdoors]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Cabling]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[configuration]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[Current threats]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Digital certificates]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[filtering]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Hubs]]></category>
		<category><![CDATA[human factors]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[Intrusion management]]></category>
		<category><![CDATA[Network management software]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Outsourcing]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[PEN testing]]></category>
		<category><![CDATA[Platform Security]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Project management]]></category>
		<category><![CDATA[provisioning]]></category>
		<category><![CDATA[Remote management]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Routers]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Single sign-on]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[SSL/TLS]]></category>
		<category><![CDATA[Switches]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<category><![CDATA[Web security]]></category>
		<category><![CDATA[Wireless]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[We are a company where we have expirience on network remote administration and now we have open a new area, The area of security. Now I need to start to make new procedures like when a new customer come to us and ask if we can handle the security for his network&#8230; I need to [...]]]></description>
				<content:encoded><![CDATA[<p>We are a company where we have expirience on network remote administration and now we have open a new area, The area of security. Now I need to start to make new procedures like when a new customer come to us and ask if we can handle the security for his network&#8230; I need to know if some one can recommend some standard like ISO, COBIT or something like this in order to make new procedures, questionnaires and all those things.</p>
<p>Thanks a Lot!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/procedures-for-a-new-area/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Compliance to Acts</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/compliance-to-acts/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/compliance-to-acts/#comments</comments>
		<pubDate>Fri, 02 Mar 2007 09:55:35 +0000</pubDate>
		<dc:creator>Rohitmagazine</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Laws]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Regulations]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[standards]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[How can softwares for url/content filtering or mail scanning be made compliant to HIPAA , Sarbanes-oxley act etc. &#8230; What all features are required to be implemented to make them compliant ????]]></description>
				<content:encoded><![CDATA[<p>How can softwares for url/content filtering or mail scanning be made compliant to HIPAA , Sarbanes-oxley act etc. &#8230;<br />
What all features are required to be implemented to make them compliant ????</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/compliance-to-acts/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/24 queries in 0.032 seconds using memcached
Object Caching 1294/1415 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-23 22:15:50 -->