<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAS 70 &#187; Incident response</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/sas-70/tag/incident-response/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/sas-70</link>
	<description></description>
	<lastBuildDate>Tue, 23 Dec 2008 17:58:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Back to basics – Security awareness and education – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/back-to-basics-%e2%80%93-security-awareness-and-education-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/back-to-basics-%e2%80%93-security-awareness-and-education-%e2%80%93-sas70/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 04:26:14 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[CIO]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/back-to-basics-%e2%80%93-security-awareness-and-education-%e2%80%93-sas70/</guid>
		<description><![CDATA[For any security program, you must start at the basics and begin with a information security plan. In a SAS 70 audit, an auditor will examine a CIO&#8217;s operations to determine that you have security program management, incident response, and that appropriate training is provided to your employees. Your security plan should include at least [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;} @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1959330536; 	mso-list-type:hybrid; 	mso-list-template-ids:1424621910 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span></span></em></p>
<p class="MsoNormal"><span>For any security program, you must start at the basics and begin with a information security plan. In a SAS 70 audit, an auditor will examine a CIO&#8217;s operations to determine that you have security program management, incident response, and that appropriate training is provided to your employees. Your security plan should include at least include: </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>Procedures to protect and provide access to IT systems and applications</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>Procedures to report incidents when they occur</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>Investigation practices required to prevent future incidents</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>The right to revoke any user access at anytime</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Training should occur regularly for all employees and no employee should be granted access to your systems without taking your company’s network security training. Do you have a plan in place? If so, send me a generic sample and I will share it with our readers. Sas70expert@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/back-to-basics-%e2%80%93-security-awareness-and-education-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS70 audits require preventative maintenance too!</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/sas70-audits-require-preventative-maintenance-too/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/sas70-audits-require-preventative-maintenance-too/#comments</comments>
		<pubDate>Mon, 22 Sep 2008 12:21:29 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[cooling systems]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/sas70-audits-require-preventative-maintenance-too/</guid>
		<description><![CDATA[During a SAS 70 audit of your DataCenter, an auditor will examine the installation of generators, cooling systems, and UPS backup systems. Questions will arise not only about installation, but of continuing preventative maintenance and incident response. An integrated approach should be followed which has is a holistic plan that clearly identifies scheduling, execution, documentation, [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1809081993; 	mso-list-type:hybrid; 	mso-list-template-ids:-1464947684 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:38.25pt; 	mso-level-number-position:left; 	margin-left:38.25pt; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><span></span></p>
<p class="MsoNormal"><span>During a SAS 70 audit of your DataCenter, an auditor will examine the installation of generators, cooling systems, and UPS backup systems. Questions will arise not only about installation, but of continuing preventative maintenance and incident response. An integrated approach should be followed which has is a holistic plan that clearly identifies scheduling, execution, documentation, risk management, and continuing follow-up inspections.</span></p>
<p class="MsoNormal"><span> When preventative maintenance occurs, four results can be expected:</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>         </span></span></span><!--[endif]--><span>a potential issue is identified and immediate actions are taken to prevent a future failure.</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>         </span></span></span><!--[endif]--><span>a potential issues is identified and a repair is scheduled</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>         </span></span></span><!--[endif]--><span>the regular maintenance does not uncover any potential repair</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>         </span></span></span><!--[endif]--><span>a defect is uncovered and unanticipated repair time occurs.</span></p>
<p class="MsoNormal"><span> In order to optimize maintenance windows, Managers should maintain the age of equipment, history of operating and environmental experience (temperature, voltage, run-time, abnormal events), and operating characteristics such as noise, temperature and vibration. Where is your preventative maintenance plan and do you have service level agreements in place today to monitor your network services? SAS70ExPERT@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/sas70-audits-require-preventative-maintenance-too/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Breaches – Do you have a plan? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/data-breaches-%e2%80%93-do-you-have-a-plan-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/data-breaches-%e2%80%93-do-you-have-a-plan-sas70/#comments</comments>
		<pubDate>Sun, 27 Jul 2008 01:46:51 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Backup]]></category>
		<category><![CDATA[Backup & recovery]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/data-breaches-%e2%80%93-do-you-have-a-plan-sas70/</guid>
		<description><![CDATA[You should have a disaster recovery plan when a data breach occurs within your Company. SAS 70 audits mostly will require you to have a plan documented, but the details of the plan are usually not adequately reviewed. Every disaster recovery plan should have basic requirements which include: Who to call when an Exchange server [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1974629696; 	mso-list-type:hybrid; 	mso-list-template-ids:-1108866778 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">You should have a disaster recovery plan when a data breach occurs within your Company. SAS 70 audits mostly will require you to have a plan documented, but the details of the plan are usually not adequately reviewed. Every disaster recovery plan should have basic requirements which include:</p>
<ol>
<li class="MsoNormal">Who to      call when an Exchange server malfunctions?</li>
<li class="MsoNormal">What      do you do when a fire occurs in your Datacenter? Do you use the fire      extinguisher? Pull the fire alarm? Or run out the front door and call the      fire department on your cell phone. There are many tasks that must be done      to prevent a catastrophe and each has to be assigned.</li>
<li class="MsoNormal">Where do      you report when the Datacenter is flooded? Do you meet at the local coffee      shop or the CIO’s home? You need to designate a safe site so that you are      quickly able to establish communication and implement the disaster      recovery plan.</li>
<li class="MsoNormal">When      does the disaster plan take effect? Is it implemented when a laptop is      lost? Or an i-Phone is missing? Or is it when a more serious virus causes      your network to go down? You have to know when to ring the disaster bells      or the CEO, CIO, CFO will not take you seriously if you call him daily      about the missing cell phone.</li>
<li class="MsoNormal">How do      stop a virus from causing your entire network from disruption or just your      access to internet or emails? Do you unplug the network or do you call      third party services and report the issue?</li>
</ol>
<p class="MsoNormal"> </p>
<p class="MsoNormal">If a disaster occurs &#8211; consider it like your home were burning….your most critical asset….a disaster recovery plan requires forethought and an impact analysis to make sure that your Company can still function on a day to day basis. Make sure you have a Disaster Recovery Plan ready for your SAS70 audit and so that you can come to work the next day. Sas70Expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/data-breaches-%e2%80%93-do-you-have-a-plan-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What’s your data loss prevention strategy? – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 04:30:32 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[business/IT alignment]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Configuration]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[Data center design]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Database issues]]></category>
		<category><![CDATA[Database Management Systems]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Intrustion management]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[management software]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network Management Systems]]></category>
		<category><![CDATA[Network monitoring]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Patch management]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[router configuration]]></category>
		<category><![CDATA[routers]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Third-party services]]></category>
		<category><![CDATA[TrendMirco]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/</guid>
		<description><![CDATA[Are you reviewing you firewall rules quarterly? Have you implemented an (IDS) intrusion detection system? Are your routers set up to prevent unauthorized intruders? Do you have the latest and greatest virus protection? Are you performing a SAS70 audit every six months? Database security breaches are increasing daily and costing tremendous amounts of dollars that [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Are you reviewing you firewall rules quarterly? Have you implemented an (IDS) intrusion detection system? Are your routers set up to prevent unauthorized intruders? Do you have the latest and greatest virus protection? Are you performing a SAS70 audit every six months? Database security breaches are increasing daily and costing tremendous amounts of dollars that should have been spent on IT projects. You should at least have an emergency plan in place when data loss occurs. Without an emergency plan in place, the breach could continue and the legal costs could continue to escalate.</p>
<p class="MsoNormal"> </p>
<p><span> <a href="http://itknowledgeexchange.techtarget.com/itanswers/tag/data-center-design/" title="Data center design (18)"><span></span></a></span><a href="http://itknowledgeexchange.techtarget.com/itanswers/tag/security-program-management/" title="Security Program Management (112)"><br />
</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
