Items related to International IT Governance: An Executive Guide to...

International IT Governance: An Executive Guide to ISO 17799/ISO 27001 - Softcover

CALDER, Alan

 
9780749447489: International IT Governance: An Executive Guide to ISO 17799/ISO 27001

Synopsis

The development of IT Governance, which recognizes the convergence between business and IT management, makes it essential for managers at all levels and in organizations of all sizes to understand how best to deal with information security risks. <i>International IT Governance </i>explores new legislation, including the launch of ISO/IEC 27001, which makes a single, global standard of information security best practice available.

"synopsis" may belong to another edition of this title.

About the Author

<b>Alan Calder</b> is a founder-director of IT Governance Ltd, which provides IT governance and information security services through its website www.itgovernance.co.uk. He is the author of <i><b>Corporate Governance</b>,<b> IT Governance</b></i> and <b><i>International IT</i> <i>Governance</i></b>, all published by Kogan Page.

Excerpt. © Reprinted by permission. All rights reserved.

<p>Introduction<br><br> The information economy<br><br> What is IT governance?<br><br> Information security<br><br> 1. Why is information security necessary?<br><br> Nature of information security threats<br><br> Prevalence of information security threats<br><br> Impacts of information security threats<br><br> Cybercrime<br><br> Cyberwar<br><br> Future risks<br><br> Legislation<br><br> Benefits of an information security management system<br><br> 2. Sarbanes-Oxley and regulatory compliance<br><br> Sarbanes-Oxley<br><br> Enterprise risk management<br><br> Regulatory compliance<br><br> IT governance<br><br> 3. Information security standards<br><br> Benefits of certification<br><br> History of ISO/IEC 27 1 and ISO/IEC 17799<br><br> Use of the standard<br><br> ISO/IEC 17799<br><br> PDCA and process approach<br><br> Structured approach to implementation<br><br> Quality system integration<br><br> Documentation<br><br> Continual improvement and metrics<br><br> 4. Organizing information security<br><br> Internal organization<br><br> Management review<br><br> Information security manager<br><br> The cross-functional management forum<br><br> ISO/IEC 27 1 project group<br><br> Approval process for information processing facilities<br><br> Product selection and the Common Criteria<br><br> Specialist information security advice<br><br> Contact with authorities and with special interest groups<br><br> Independent review of information security<br><br> Summary<br><br> 5. Information security policy and scope<br><br> Information security policy<br><br> A policy statement<br><br> Costs and monitoring progress<br><br> 6. The risk assessment and statement of applicability<br><br> Establishing security requirements<br><br> Risks, impacts and risk management<br><br> Selection of controls and statement of applicability<br><br> Gap analysis<br><br> Risk assessment tools<br><br> Risk treatment plan<br><br> 7. External parties<br><br> Identification of risks related to external parties<br><br> Types of access<br><br> Reasons for access<br><br> Outsourcing<br><br> On-site contractors<br><br> Addressing security when dealing with customers<br><br> Addressing security in third party agreements<br><br> 8. Asset management<br><br> Asset owners<br><br> Inventory<br><br> Acceptable use of assets<br><br> Information classification<br><br> The US government classification system<br><br> Unified classification markings<br><br> Information labeling and handling<br><br> Non-disclosure agreements and trusted partners<br><br> 9. Human resources security<br><br> Job descriptions and competence requirements<br><br> Screening<br><br> Terms and conditions of employment<br><br> During employment<br><br> Disciplinary process<br><br> Termination or change of employment<br><br> 10. Physical and environmental security<br><br> Secure areas<br><br> Public access, delivery and loading areas<br><br> 11. Equipment security<br><br> Equipment siting and protection<br><br> Supporting utilities<br><br> Cabling security<br><br> Equipment maintenance<br><br> Security of equipment off-premises<br><br> Secure disposal or reuse of equipment<br><br> Removal of property<br><br> 12. Communications and operations management<br><br> Documented operating procedures<br><br> Change management<br><br> Segregation of duties<br><br> Separation of development, test and operational facilities<br><br> Third party service delivery management<br><br> Monitoring and review of third party services<br><br> Managing changes to third party services<br><br> System planning and acceptance<br><br> 13. Controls against malicious software (malware) and back-ups<br><br> Viruses, worms and Trojans<br><br> Anti-malware software<br><br> Hoax messages<br><br> Anti-malware controls<br><br> Airborne viruses<br><br> Controls against mobile code<br><br> Back-up<br><br> 14. Network security management and media handling<br><br> Network management<br><br> Media handling<br><br> 15. Exchanges of information<br><br> Information exchange policies and procedures<br><br> Exchange agreements<br><br> Physical media in transit<br><br> Business information systems<br><br> 16. Electronic commerce services<br><br> E-commerce issues<br><br> Security technologies<br><br> Server security<br><br> Online transactions<br><br> Publicly available information<br><br> 17. E-mail and internet use<br><br> Security risks in e-mail<br><br> Misuse of the internet<br><br> Internet acceptable use policy (AUP)<br><br> 18. Access control<br><br> Hackers<br><br> Hacker techniques<br><br> System configuration<br><br> Access control policy<br><br> User access management<br><br> Clear desk and clear screen policy<br><br> 19. Network access control<br><br> Networks<br><br> Network security<br><br> 20. Operating system access control<br><br> Secure log-on procedures<br><br> User identification and authentication<br><br> Password management system<br><br> Use of system utilities<br><br> Session time-out<br><br> Limitation of connection time<br><br> 21. Application access control and teleworking<br><br> Application and information access control<br><br> Mobile computing and teleworking<br><br> 22. Systems acquisition, development and maintenance<br><br> Security requirements analysis and specification<br><br> Correct processing in applications<br><br> 23. Cryptographic controls<br><br> Encryption<br><br> Public key infrastructure (PKI)<br><br> Digital signatures<br><br> Non-repudiation services<br><br> Key management<br><br> 24. Security in development and support processes<br><br> System files<br><br> Access control to program source code<br><br> Development and support processes<br><br> Vulnerability management<br><br> 25. Monitoring and information security incident management<br><br> Monitoring<br><br> Information security events<br><br> Management of information security incidents and improvements<br><br> 26. Business continuity management<br><br> Business continuity management process<br><br> Business continuity and risk assessment<br><br> Developing and implementing continuity plans<br><br> Business continuity planning framework<br><br> Testing, maintaining and reassessing business continuity plans<br><br> 27. Compliance<br><br> Identification of applicable legislation<br><br> Intellectual property rights (IPR)<br><br> Safeguarding of organizational records<br><br> Data protection and privacy of personal information<br><br> Prevention of misuse of information processing facilities<br><br> Regulation of cryptographic controls<br><br> Compliance with security policies and standards<br><br> Information systems audit considerations<br><br> 28. The ISO/IEC 27 1 audit<br><br> Selection of auditors<br><br> Initial visit<br><br> Preparation for audit<br><br> Appendices<br><br> I. Useful websites<br><br> II. Further reading</p>

"About this title" may belong to another edition of this title.