One in three companies experienced at least one DDoS attack in the last twelve months


One in three organizations (31 percent) has suffered one or more Distributed Denial of Service (DDoS) attacks in the last 12 months, according to independent research commissioned by Corero Network Security.

Continue reading One in three companies experienced at least one DDoS attack in the last twelve months

Tags: , ,

Disaster recovery and contingency planning security considerations


In a disaster, all focus is — naturally — on getting critical business processes back up and running. Whether the disaster is natural or manmade, it’s all about recovering business operations as fast as possible, getting employees back to work, and avoiding costly downtime.

Continue reading Disaster recovery and contingency planning security considerations

Tags: , ,

Study: Cost of data breach in U.S. is highest world wide


A global study of data breach costs conducted by the Ponemon Institute finds notification laws have dramatic impact on the price tag.

Continue reading Study: Cost of data breach in U.S. is highest world wide

Tags: , ,

How to study for the CISSP examination


Studying for the CISSP (Certified Information Systems Security Professional) examination?

See How to study for the CISSP examination, by Ernie Hayden.

Tags: , , , ,

Infosec: Cybercriminals move up the stack – but so does data protection


Cybercriminals have approached data theft in a methodical way, starting at the bottom of the technology stack and working their way up to the top – the applications layer.

See Cybercriminals move up the stack – but so does data protection by Gary Palgon, via SC Magazine [Secure Computing].

Tags: , , , , ,

Building A Business Case For Information Security


If the economic downturn has proven anything, it’s that many CISOs still struggle to articulate the value of their security programs and justify the security budget to business and executive management. Many helplessly watched their budgets slashed, their projects postponed, and their employees laid-off.

Continue reading Building A Business Case For Information Security

Tags: , , ,

Risk Management Framework: Helping Organizations Implement Effective Information Security Programs


The management of risks to information technology (IT) systems is a fundamental component of every organization’s information security program. An effective risk management process enables an organization to protect its information assets and supports its ability to carry out its mission successfully. The Information Technology Laboratory of the National Institute of Standards and Technology (NIST) has developed a Risk Management Framework that integrates the essential steps of the risk management process to support organizational managers in making informed decisions regarding the security of their information systems.

Continue reading Risk Management Framework: Helping Organizations Implement Effective Information Security Programs

Tags: , , , , ,

Survey: Downturn in spending risks future information security


The downturn in security investments and vulnerabilities in social networking are regarded as major threats to corporate information security, according to research from Deloitte Touche Tohmatsu.

Continue reading Survey: Downturn in spending risks future information security

Tags: , , , ,

European Network and Information Security Agency: IT Continuity Resources


The European Network and Information Security Agency (ENISA) site’s purpose is to: “Promote Risk Assessment and Risk Management methods to enhance the capability of dealing with network and information security threats” [ENISA Regulation].

Continue reading European Network and Information Security Agency: IT Continuity Resources

Tags: , , ,

SPECIAL OFFER: Information Security Policies Made Easy – Save $100 plus free standard shipping


Information Security Policies Made Easy is your definitive resource for a comprehensive information security policies for your enterprise.

Until April 30, 2009, Rothstein Associates is offering a $100 discount on this valuable tool – including both print AND CD-ROM – regularly $795, now only $695.00 PLUS FREE STANDARD SHIPPING! (prepaid orders only).

Information Security Policies Made Easy is the “gold standard” information security policy resource based on the 25 year consulting experience of Charles Cresson Wood, CISSP, CISA. The most complete security policy library available, ISPME contains over 1360 pre-written information security policies covering over 200 security topics and organized in ISO 17799 format. Take the work out of creating, writing, and implementing security policies!

Information Security Policies Made Easy has everything you need to save time and money building or updating written security policies, including:

1. A complete information security policy library with over 1360 individual pre-written security policies including:

  • Coverage of the latest technical, legal and regulatory issues
  • ISO 17799 outline format, allowing for easy gap-analysis against existing standards and security frameworks
  • Expert commentary discussing the risks mitigated by each policy
  • Target audience (management, technical, or user) and security environment (low, medium, high) for each policy
  • Policy coverage maps for Sarbanes-Oxley (COBIT) and HIPAA security

2. Eighteen complete pre-written security policy documents that every company should have, updated and ready to use “as is” or with easy customization, including:

  • User-targeted policies such as: Electronic Mail Policy, Internet Security Policy for End Users and Web Privacy Policy
  • Organization-wide policies such as: High-Level Security Policy, Privacy policy, Information Ownership Policy
  • Technology-based policies such as: Firewall Policy, Data Classification Policy and Network Security Policy
  • Sample risk acceptance memo for the approval of out of compliance situations, a sample non-disclosure agreement, and a user policy acceptance agreement.

3. Expert advice on the security policy development and review process, including:

  • A step-by-step checklist of security policy development tasks to quickly start a policy development project
  • Helpful tips and tricks for getting management buy-in for information security policies and education
  • Tips and techniques for raising security policy awareness
  • Real-world examples of problems caused by missing or poor information security policies
  • Policy development resources such as Information Security Periodicals, professional associations and related security organizations

4. All content included on an easy-to-use CD-ROM with an indexed and searchable HTML interface for easy location, featuring:

  • Policies available in HTML, PDF, MS-Word format
  • Easy cut-and-paste into existing corporate documents
  • Extensive cross-references between policies that help the user quickly understand alternative solutions and complimentary controls

Information Security Policies Made Easy covers virtually every aspect of corporate information security including:

  • Privacy issues
  • Identity Theft
  • Web pages
  • Firewalls
  • Employee surveillance
  • Electronic commerce
  • Digital signatures
  • Computer viruses
  • Encryption
  • Contingency planning
  • Logging controls
  • Internet
  • Intranets
  • Corporate Governance
  • Outsourcing security functions
  • Computer emergency response teams
  • Microcomputers
  • Local area networks
  • Voice Over IP
  • Password selection
  • Electronic mail
  • SPAM Prevention
  • Data Classification
  • Telecommuting
  • Telephone systems
  • Portable computers
  • User security training
  • Information Security Related Terrorism

=====================================================================

To receive your $100 discount and free standard ground shipping (or equivalent discount), either click below, OR go to the full product description of Information Security Policies Made Easy and enter Coupon Code “ispme09” at checkout. Discount applies to prepaid orders only. Shipping charge will be adjusted at time of shipment.

=====================================

Take advantage of this limited offer on Information Security Policies Made Easy!

Tags: , , , , ,

SPECIAL OFFER: Information Security Policies Made Easy – Save $100 plus free standard shipping


Information Security Policies Made Easy is your definitive resource for a comprehensive information security policies for your enterprise.

Until April 30, 2009, Rothstein Associates is offering a $100 discount on this valuable tool – including both print AND CD-ROM – regularly $795, now only $695.00 PLUS FREE STANDARD SHIPPING! (prepaid orders only).

Information Security Policies Made Easy is the “gold standard” information security policy resource based on the 25 year consulting experience of Charles Cresson Wood, CISSP, CISA. The most complete security policy library available, ISPME contains over 1360 pre-written information security policies covering over 200 security topics and organized in ISO 17799 format. Take the work out of creating, writing, and implementing security policies!

Information Security Policies Made Easy has everything you need to save time and money building or updating written security policies, including:

1. A complete information security policy library with over 1360 individual pre-written security policies including:

  • Coverage of the latest technical, legal and regulatory issues
  • ISO 17799 outline format, allowing for easy gap-analysis against existing standards and security frameworks
  • Expert commentary discussing the risks mitigated by each policy
  • Target audience (management, technical, or user) and security environment (low, medium, high) for each policy
  • Policy coverage maps for Sarbanes-Oxley (COBIT) and HIPAA security

2. Eighteen complete pre-written security policy documents that every company should have, updated and ready to use “as is” or with easy customization, including:

  • User-targeted policies such as: Electronic Mail Policy, Internet Security Policy for End Users and Web Privacy Policy
  • Organization-wide policies such as: High-Level Security Policy, Privacy policy, Information Ownership Policy
  • Technology-based policies such as: Firewall Policy, Data Classification Policy and Network Security Policy
  • Sample risk acceptance memo for the approval of out of compliance situations, a sample non-disclosure agreement, and a user policy acceptance agreement.

3. Expert advice on the security policy development and review process, including:

  • A step-by-step checklist of security policy development tasks to quickly start a policy development project
  • Helpful tips and tricks for getting management buy-in for information security policies and education
  • Tips and techniques for raising security policy awareness
  • Real-world examples of problems caused by missing or poor information security policies
  • Policy development resources such as Information Security Periodicals, professional associations and related security organizations

4. All content included on an easy-to-use CD-ROM with an indexed and searchable HTML interface for easy location, featuring:

  • Policies available in HTML, PDF, MS-Word format
  • Easy cut-and-paste into existing corporate documents
  • Extensive cross-references between policies that help the user quickly understand alternative solutions and complimentary controls

Information Security Policies Made Easy covers virtually every aspect of corporate information security including:

  • Privacy issues
  • Identity Theft
  • Web pages
  • Firewalls
  • Employee surveillance
  • Electronic commerce
  • Digital signatures
  • Computer viruses
  • Encryption
  • Contingency planning
  • Logging controls
  • Internet
  • Intranets
  • Corporate Governance
  • Outsourcing security functions
  • Computer emergency response teams
  • Microcomputers
  • Local area networks
  • Voice Over IP
  • Password selection
  • Electronic mail
  • SPAM Prevention
  • Data Classification
  • Telecommuting
  • Telephone systems
  • Portable computers
  • User security training
  • Information Security Related Terrorism

=====================================================================

To receive your $100 discount and free standard ground shipping (or equivalent discount), either click below, OR go to the full product description of Information Security Policies Made Easy and enter Coupon Code “ispme09” at checkout. Discount applies to prepaid orders only. Shipping charge will be adjusted at time of shipment.

=====================================

Take advantage of this limited offer on Information Security Policies Made Easy!

Tags: , , , , ,