Information Availability & Security Nuggets (2008/09 GUIDE)

Page 88

Page 93

Page 103

Online


Center for Internet Security Free Benchmarks

The Center for Internet Security (CIS) is a non-profit enterprise whose mission is to help organizations reduce the risk of business and e-commerce disruptions resulting from inadequate technical security controls. The practical CIS Benchmarks support available high level standards that deal with the "Why, Who, When, and Where" aspects of IT security by detailing "How" to secure an ever widening array of workstations, servers, network devices, and software applications in terms of technology specific controls. CIS Scoring Tools analyze and report system compliance with the technical control settings in the Benchmarks.

The CIS Benchmarks are available for download free of charge to the Internet community from this web site.

www.cisecurity.org/charter.html


Lots of Good Stuff from InfoSecurity Guru Kevin Beaver

You may need to do a quick third-party registration to access certain links.


Two Near-Disasters Highlight Backup/Recovery Deficiencies

Jon Toigo discusses a recent regional disaster in which a large company will quickly discover that the damage to small firms in the area can dramatically reduce its own recovery.

www.esj.com/storage/article.aspx?EditorialsID=3257


Fusion Risk Management White Paper

Fusion’s latest white paper, Achieving Risk Management Maturity, addresses the challenges that businesses face when managing business risk related to the use of Information Technology, as well as related to business operations.

The current state of affairs related to risk management in American businesses both large and small will be explored. This paper then highlights the importance of risk management to the business in normal times, as well as in times of crisis. The shortcomings of traditional risk management techniques will also be explained, noting the high level trends that demand new approaches.

www.fusionriskmgmt.com/fusion_latest_thinking.html


From IT Security

Security Audit

Firewalls

Complying with Data-Privacy Laws
Make sure your company meets new data-management regulations.

As companies and consumers become increasingly reliant on mobile technology, more laws are being enacted to ensure data security. Find out if your business is up-to-speed on the most recent regulations by reading this free white paper. With this guide, you'll understand the most important developments in data security, including:

  • Changes to the Federal Rules of Civil Procedure
  • Legal consequences of lost or irretrievable information
  • The best tools to secure data on mobile devices

Register now to download this free white paper and learn more.

www.itsecurity.com/whitepaper/complying-data-privacy-laws-nokia/


New Resources from SunGard


From CSO Online

Terrific Articles to Check out!

www.csoonline.com/topic/41248/Business_Continuity

How to Evaluate BC/DR Consultants
Stacy Collett offers five questions to help weed out the posers from the real deal. Plus: a checklist of topics a BC/DR consultant should know.
www.csoonline.com/article/433414/How_to_Evaluate_BC_DR_Consultants

Iowa's Floods: Tragic Lesson in Business Continuity
For security administrator Deb Hale, the recent tornadoes and floods in Iowa hit close to home and provided a sobering lesson in business continuity.
www.csoonline.com/article/425513/Iowa_s_Floods_Tragic_Lesson_in_Business_Continuity

5 Ways to Build a Business Case for Business Continuity
To win support for a business continuity plan, emphasize ways it can give your company a competitive edge.
www.csoonline.com/article/221615/
_Ways_to_Build_a_Business_Case_for_Business_Continuity?contentId=221615&slug=&

Five Steps to Evaluating Business Continuity Services
A do-it-yourself approach to business continuity has its advantages but isn't right for everyone.
www.csoonline.com/article/221306/
Five_Steps_to_Evaluating_Business_Continuity_Services?contentId=221306&slug=&

Five Ways to Turn Employees into Security Assets for Protecting Data
Trend Micro's Glen Kosaka explains how to prevent data leaks by raising security awareness and gaining employee support
www.csoonline.com/article/343968/
Five_Ways_to_Turn_Employees_into_Security_Assets_for_Protecting_Data

Monitoring the Enemy Within: Reflections on a New Internal Data Theft Study
Who steals data, and what do they do with it? Cooper Bachman of ID Analytics scrutinizes research from a dozen data thefts resulting in 1,300 attempted instances of data misuse.
www.csoonline.com/article/443371/
Monitoring_the_Enemy_Within_Reflections_on_a_New_Internal_Data_Theft_Study

New to Network Security?
Before you get lost in the bits and bytes, Stephen Northcutt of SANS provides a look at the essential concepts.
www.csoonline.com/article/342820/
Network_Security_The_Basics?contentId=342820&slug=&

Incident Detection, Response, and Forensics: The Basics
Richard Bejtlich on how to build an effective cyber incident detection and response mechanism in your organization.
www.csoonline.com/article/205960/
Incident_Detection_Response_and_Forensics_The_Basics?contentId=205960&slug=&

Focus On The Human Factor, Security Panel Says
Security experts say the human factor should be the focal point of security governance, not technology
www.csoonline.com/article/441020/
Focus_On_The_Human_Factor_Security_Panel_Says


Whitepaper From ISSA

Biggest Information Security Mistakes that Organizations Make, and How to Avoid Making Them
Information security mistakes are costly, damaging and all too prevalent. Given the obvious repercussions of poor security strategies, one is inclined to believe change agents are in place; however, organizations continue to make seemingly avoidable mistakes when it comes to information security. This is due to misconceptions and common mistakes that are repeated. This article introduces five common information security mistakes that organizations make and concludes with recommendations and best practices for building and maintaining a successful information security practice and avoiding these mistakes. To read the white paper, click here.

www.issa.org/Resources/Whitepapers.html


New Resources from ISACA

Information assurance is the bedrock upon which enterprise decision-making is built. Without assurance, enterprises cannot feel certain that the information upon which they base their mission-critical decisions is reliable, confidential, secure and available when needed. ISACA has long served the information systems audit and assurance community, since its inception in 1969. Available for free download:

  • Top Business/Technology Issues Survey Results
  • ITAF™: A Professional Practices Framework for IT Assurance!

Complimentary Download (PDF, 650K)


Best Practices Guides from ISAlliance

These guides helps to catalyze a risk-management based approach to ensuring the survivability and security of critical information assets. The best practices contained represent the 10 highest priority and most frequently recommended security practices as a place to start for today's operational systems. Three free downloads are available.

www.isalliance.org/index.php?option=com_performs&formid=3&Itemid=165


Liberty Alliance Releases Guidelines for Data Management

Businesses now have new guidelines for sharing and protecting sensitive data. The Liberty Alliance, a coalition of businesses and other organizations, has released new frameworks which can help create new efficiencies in data handling.

Liberty Alliance, the global identity community working to build a more trust-worthy internet for consumers, governments and businesses worldwide, has announced the first public release of the protocol independent Liberty Identity Assurance Framework (IAF). The IAF details four identity assurance levels to ease and speed the process of linking trusted identity-enabled enterprise, social networking and Web 2.0 applications together based on standardized business rules and security risks associated with each level of identity assurance. Liberty Alliance will launch an IAF identity assurance accreditation and certification program during 3Q 08.

The first version of the Liberty Alliance Identity Assurance Framework released is available for download.

www.projectliberty.org/liberty/news_events/press_releases/
liberty_alliance_releases_identity_assurance_framework


HumaniNet Provides Technology Assistance to Humanitarian Organizations

HumaniNet was founded in 2002 by a group of volunteers in the United States who recognized the acute need for technology assistance to humanitarian organizations. Since then, HumaniNet has grown to become a cooperative network of over 100 field organizations, several supporting technology businesses, and a group of expert volunteers who help with research and analysis, finding the best practices, and sharing field results in global information and communication technologies, or ICT. This informal alliance consists of several constituencies:

Field partners. A fast-growing, informal alliance of nonprofit humanitarian and mission organizations whom we assist and who share their observations and field results in global information and communication technologies, or ICT.

Technology partners. We have formed cooperative and productive relationships with experts in a variety of ICT areas and with companies and leaders who understand the needs and challenges facing the humanitarian community.

Funding partners. Our donors make it possible for us to deliver the information and assistance that humanitarian teams need. We acknowledge their contributions to HumaniNet and to the "people who help people."

HumaniNet Project Team. The HumaniNet Project Team is a growing group of experienced and committed volunteers who give of their time, talents, and resources to further the HumaniNet vision.

Leadership. Meet our executive director, board, and advisory council.

www.humaninet.org/about.html


Business Continuity Research by IDG

IDG Research conducted a survey among senior IT leaders in March 2008 to learn about companies' overall business continuity preparedness, the impact of the current economy and the role of virtualization in business continuity/disaster recovery plans. Read this research report to see the results, explore what has changed from last year's research, and see what companies are planning next for their business continuity plans.

www.cio.com/white-paper/429514/Business_Continuity_Research


DHS Will Enhance Homeland Security Information Network (HSIN)

The U.S. Department of Homeland Security (DHS) announced today that it is taking steps to enhance its Homeland Security Information Network (HSIN). Known as HSIN Next Generation (NextGen), the enhancement will provide a secure and trusted national platform for Sensitive But Unclassified (SBU) information sharing and collaboration between federal, state, local, tribal, territorial, private sector, and international partners.

HSIN Next Generation will update the current HSIN technology to better enable Homeland Security to meet the requirements of a trusted and secure environment, combined with enhanced capabilities in many areas.

HSIN NextGen will provide DHS, DHS partners, and stakeholders information management capabilities and services including a portal, search, collaboration, enterprise content management, and Service Oriented Architecture-based information integration and analysis functions to facilitate their collaboration and information sharing needs for SBU data.

www.dhs.gov/xnews/releases/pr_1212787226112.shtm


Cyber Security Guide for Small Business

The U.S. Chamber of Commerce and the Internet Security Alliance Cyber Security Guide have published a guide to help small businesses. The publication: Commonsense Guide to Cyber Security for Small Businesses is available to download.

www.ready.gov/business/protect/cybersecurity.html


From CIO.com

Consolidated Disaster Recovery Using Virtualization
This white paper provides an overview of how server virtualization is modernizing disaster recovery. Find out how virtualization, together with workload portability technologies, enables organizations to implement a disaster recovery plan that is more affordable and flexible than traditional options, while providing rapid restore times and enterprise-level workload protection.
Download Now

A Practical Roadmap for Comprehensive Data Protection
Data protection is preparation for and recovery from data emergencies. Data emergencies are corruption and damage mainly resulting from operational mishaps or disastrous events. Backup, monitoring, and replication contribute to recovery. Each task is only part of a data protection solution. A data protection solution also involves best practices, services, and technology, Download Now

Reduce the Risk of Costly Data Breaches: Three Pillars of Data Protection
This paper provides an overview of PC encryption, the elements beyond encryption that are necessary for a complete data protection solution.
Download Now

Eight Quick Ways to Get Your Site Blacklisted
Effective online communication relies on your ability to reach customers. If your e-mail or newsletters are listed on a spam blacklist, the messages won't get through. Here are several common mistakes that put business communication at risk.
www.cio.com/article/443866/Eight_Quick_Ways_to_Get_Your_Site_Blacklisted

How to Prevent a Data Disaster
Seven ways you can expand your backup portfolio to protect against the inevitable data catastrophe.
www.cio.com/article/390963/How_to_Prevent_a_Data_Disaster


CSI Computer Crime and Security Survey Shows Average Cyber-Losses Jumping After Five-Year Decline

The Computer Security Institute (CSI) released its 2007 report with news that the average annual loss reported by U.S. companies in the 2007 CSI Computer Crime and Security Survey more than doubled, from $168,000 in last year's report to $350,424 in this year's survey. This ends a five-year run of lower reported losses.

Financial fraud overtook virus attacks as the source of the greatest financial loss. Virus losses, which had been the leading cause of loss for seven straight years, fell to second place. Another significant cause of loss was system penetration by outsiders.

Additional key findings include:

  • Almost one-fifth of those respondents who suffered one or more kinds of security incident said they'd suffered a "targeted attack," i.e. a malware attack aimed exclusively at their organization or at organizations within a small subset of the general population.
  • Insider abuse of network access or e-mail (such as trafficking in pornography or pirated software) edged out virus incidents as the most prevalent security problem, with 59% and 52% of respondents reporting each respectively.
  • When asked generally whether they'd suffered a security incident, 46% of respondents said yes, down from 53% last year and 56% the year before.

"At a period when experts throughout the industry have been discussing with concern the growing sophistication and stealth of cyber attacks, here we have a couple hundred respondents saying they lost significantly more money last year," states Robert Richardson, CSI director and author of the survey. "There's a strong suggestion in this year's results that mounting threats are beginning to materialize as mounting losses."

The complete CSI/FBI Computer Crime and Security Survey is available for free download on the CSI Web site.

www.gocsi.com/forms/csi_survey.jhtml


From SearchSecurity

Data Lifecycle Security Essentials
Data protection information flows through business processes in an orderly fashion; security must flow right along with it.

Information Security and Business Integration
Integration security professionals can rely on the same models and frameworks used by traditional business to earn a seat at the table.

http://searchsecurity.techtarget.com/magazineCurrent/0,296884,sid14,00.html



Back to the top