Author Archive

James Warren

James Warren

Internet Marketing Manager at IT Governance since March 2008.




The lesser known benefit ISO 14001

February 29th, 2012 by

Organisations have implemented the ISO 14001 Environmental Management System standard for many reasons. From a corporate social responsibility standpoint, it demonstrates that a company is committed to reducing its carbon footprint.

The lesser known benefit of achieving certification against ISO 14001 is the savings you will make in real financial terms.

“The savings have been tremendous. At the start there was a degree of scepticism about the benefits of ISO14001: now everybody buys in.”
Lauren McHugh – Data Quality Analyst – London Pensions Fund Authority (LPFA).

ISO 14001 Environmental Management System Documentation Toolkit ISO 14001 Environmental Management System Documentation Toolkit

RRP: £199.00
Price: £149
You Save:£50.00

Buy Today!

Learn more

Buy Now

 

This unique toolkit contains a full suite of documentation templates that will help you prepare for and implement an environmental management system (EMS) that complies with ISO14001, the environmental management system standard.

Buy the ISO14001 EMS Toolkit today!

More to explore …

Green IT in Practice, Second edition
Green IT in Practice, Second edition
by Gary Hird

Learn more

Buy Now

The Green Agenda: A Business Guide
The Green Agenda: A Business Guide

Learn more

Buy Now

Compliance for Green IT: Pocket Guide
Compliance for Green IT: Pocket Guide

Learn more

Buy Now

30% Off COBIT Foundation Training

February 27th, 2012 by

Our 2 day COBIT Foundation Course, delivered by an experienced ISACA-licensed trainer, gives the delegate an introduction to the benefits of a sound IT governance framework, and explains how they can be realised using the COBIT best practice framework.

With just a few spaces remaining on our 19-20 March 2012 course, we are offering a 30% discount if you book before the end of February.

COBIT Foundation (2 day) Course COBIT Foundation (2 day) Course
19-20 March 2012 in London

RRP: £895
Price: £626.50
You Save:£268.50 (30%)

Very limited availability – book now!

Learn more

Buy Now

 

More to explore …

ISO27001 Certified ISMS Foundation Training
ISO27001 Certified ISMS Foundation Training
30% off March course!

Learn more

Buy Now

PCI Foundation Training
PCI Foundation Training
29 March 2012

Learn more

Buy Now

ISO27001 Certified ISMS Lead Implementer Masterclass
ISO27001 Certified ISMS Lead Implementer Masterclass
20-22 March 2012

Learn more

Buy Now

30% Off ISO27001 Certified ISMS Foundation Training

February 27th, 2012 by

Our one-day ISO27001 Certified ISMS Foundation Training course is designed for anyone in an organisation that is interested in, or about to undertake, an ISO27001 project.

With just a few spaces remaining on our 6th March 2012 course, we are offering a 30% discount if you book before the end of February.

ISO27001 Certified ISMS Foundation Training ISO27001 Certified ISMS Foundation Training
06 March 2012 in London

RRP: £494.00
Price: £345.80
You Save:£248.20 (30%)

Very limited availability – book now!

Learn more

Buy Now

 

More to explore …

COBIT Foundation (2 day) Course
COBIT Foundation (2 day) Course
30% off March course!

Learn more

Buy Now

PCI Foundation Training
PCI Foundation Training
29 March 2012

Learn more

Buy Now

ISO27001 Certified ISMS Lead Implementer Masterclass
ISO27001 Certified ISMS Lead Implementer Masterclass
20-22 March 2012

Learn more

Buy Now

Weekend Read: An Introduction to Hacking & Crimeware

February 24th, 2012 by

Cyber security will feature high on the boards agenda in 2012. This handy pocket guide provides you with a valuable list of up-to-date, authoritative sources of information, so you can stay abreast of new developments and safeguard your business.

Available in a format suitable for any eReader, you should buy today and read this weekend:

 

An Introduction to Hacking & Crimeware: A Pocket Guide An Introduction to Hacking & Crimeware: A Pocket Guide
by Victoria Loewengart

RRP: £14.95
Price: £12.95
You Save: £2.00

Learn more

Buy Now

 

More to explore …

21st Century Chinese Cyberwarfare (Pre-order)
21st Century Chinese Cyberwarfare
(Pre-order)

Learn more

Buy Now

Cyber Risks for Business Professionals: A Management Guide
Cyber Risks for Business Professionals: A Management Guide

Learn more

Buy Now

Assessing Information Security: Strategies, Tactics, Logic and Framework
Assessing Information Security: Strategies, Tactics, Logic and Framework

Learn more

Buy Now

Combat Cyber Threats: Implement ISO 27001 and create an effective ISMS!

February 23rd, 2012 by

Following the high profile rise of mass-hacking incidents in 2011 – Sony for example – ‘Cyber Attack’ could be the largest threat to your business this year.

It is a mandatory requirement for UK public sector organisation to inform the Information Commissioner’s Office of a data breach. The same legislation is not ‘currently’ enforced in the UK private sector (although it is in certain states in North America).

This notification law is actually irrelevant as hacking groups, such as ‘Annonymous’, tend to let the cat out of the bag (usually via Twitter), to announce a successful hack, sometimes before the victim organisation are aware themselves!

Gone are the days that you could brush your insecurities under the carpet.

As soon as a cyber attack is announced on Twitter, the media will ensure your customers are aware. As soon as your customers are aware, they will cut-and-run. There’s no such thing as brand loyalty when people’s personal information is at risk. The result of this negative publicity can end up with your share price tumbling (again, look at Sony), which will no-doubt result in members of the board resigning before they are fired.

Your focus need to be on protecting your business from cyber attack.
The best way to do this is to align your information security management system to ISO 27001 – the world’s only recognised cyber security management system standard.

Use the ISO27001 Cyber Security Toolkit to implement ISO 27001, create an effective ISMS and combat cyber threats!

ISO27001 Cyber Security Toolkit ISO27001 Cyber Security Toolkit
Buy during February and get a free Cyber Security Self Assessment Tool!

RRP: £1,864.00
Price: £1,695
You Save: £169.00

Learn more

Buy Now

     

This toolkit provides all the tools and resources you need to implement your own cyber security project and align your business with ISO 27001, the world’s only cyber security standard.

Protect your business and kick start your cyber security project with this toolkit today!

Quick, cost-effective DPA compliance

February 22nd, 2012 by

There is a standard approach towards achieving DPA compliance:

  • Understand what the DPA is how it affects your business
  • Identify your current level of conformance to the DPA
  • Identify gaps and steps to achieve compliance
  • Document your DPA policies
  • Understand how to react if you suffered a data breach
  • Initiate DPA staff training.

Our Complete Data Protection Toolkit contains everything you need to use this recommended approach.

Complete Data Protection Toolkit Complete Data Protection Toolkit
For quick, cost-effective DPA compliance!

Price: £156
Buy during February and get a free ICT Strategy Toolkit!

Learn more

Buy Now

     

Ensure you organisation avoids fines and brand damage and become DPA Compliant today!

Buy this toolkit before the end of February and get a free ICT Strategy Toolkit!

Quick and cost-effective PCI DSS Compliance

February 22nd, 2012 by

Achieving compliance with the payment card industry data security standard (PCI DSS), is not something that organisations can ignore.

Failure to comply can be costly, especially if a breach occurs. Penalties could be levied at three levels. First, for non-compliance by one or more of the card brands. Second, for the breach itself. Third, if the leaking of payment card data is part of a broader data loss event, there could be fines from other regulators, including the Information Commissioner’s Office and the Financial Services Authority.

This PCI DSS toolkit is specifically designed to assist payment card-accepting organisations become PCI DSS compliant.

PCI DSS v2.0 Documentation Compliance Toolkit PCI DSS v2.0 Documentation Compliance Toolkits

Price: Just £249.95
Buy before the end of February and get a free ICT Strategy Toolkit!

Learn more

Buy Now

     

This toolkit will guide you through:

  • Understanding the PCI DSS Standard
  • The initial PCI DSS Self-Assessment Questionnaire
  • Data storage Do’s and Dont’s
  • Creating a Roadmap
  • Guidance on implementation and how to complete the document templates.

With this toolkit you can protect your brand and simplify the process of becoming PCI compliant.

Buy this toolkit before the end of February and get a free ICT Strategy Toolkit!

Want a trouble-free, rapid deployment of ITIL?

February 22nd, 2012 by

Organisations that are implementing business and IT Service Management want a trouble-free, rapid deployment approach that will maximise benefits and will minimise delays and cost. Effective management, process and procedure documentation is an essential to achieving those results.

The ITSM, ITIL® & ISO/IEC 20000 Implementation Toolkit helps organisations implement service management and using ITIL practices to prepare for successful ISO/IEC 20000 certification. It will help organisations avoid costly trial-and-error dead-ends, and ensure everything is covered by using current ITIL best practices.

ITSM, ITIL & ISO/IEC 20000 Implementation Toolkit ITSM, ITIL® & ISO/IEC 20000 Implementation Toolkit
by ITSM gurus Shirley Lacy and Jenny Dugmore

Price: £495
Buy during February and get a free ICT Strategy Toolkit!

Learn more

Buy Now

     

This toolkit will be particularly useful to:

  • Organisations that must deliver quality services whilst meeting governance, regulatory and legal requirements.
  • Organisations that can benefit from improved services and service management.
  • Managers, consultants and implementers that want a quick and effective approach to setting up, implementing and improving service management.
  • Assessors and auditors who are to review or audit a service management capability or service management system against the requirements of ISO/IEC 20000-1.
  • People involved in procuring, in sourcing or outsourcing services.
  • Projects that need to deliver IT enabled services underpinned by effective service management.
  • Users of ISO/IEC 20000-5 that need to understand the implementation requirements of the 2011 edition of ISO/IEC 20000-1.

BUY this vital toolkit today and succeed in your ITSM, ITIL & ISO/IEC 20000 implementation and improvement projects!

Cost-effective route to ISO 27001 certification readiness

February 21st, 2012 by

Achieving ISO 27001 certification is the best way for an organisation to protect its information assets, mitigate the risk of Cyber attack (and other forms of data breach), and to win new business.

Risk assessment is critical to effective deployment of an ISO 27001 Information Security Management System (ISMS), and the hardest part of achieving ISO 27001 certification is the documentation.

A toolkit can accelerate your ISO 27001 project immensely. It enables a cost-effective route to certification readiness and the No 3 ISO27001 Comprehensive ISMS Toolkit has everything you will need.

No 3 ISO27001 Comprehensive ISMS Toolkit<br />
No 3 ISO27001 Comprehensive ISMS Toolkit
Buy during February and get a free ICT Strategy Toolkit!

RRP: £1,931.90
Price: £1,795
You Save: £136.90

Learn more

Buy Now

     

When you use our highly practical and informative books and tools to help you tackle the project, you receive unique guidance and support for your organisation – plus, with this package, you save money.

 

What does this toolkit contain?

 

Using the templates, was the only way that we could deliver a 1st edition ISMS in under 6 months. Our deliverable was a work in progress but miles ahead of where they would have been without the templates.
Tim Moreton, President, Moreton & Co., airlinetechnology.net.

Accelerate your ISO27001 project with the help of this toolkit. Don’t hesitate – buy it today.

How Cheshire East Council could have avoided £80K fine for just £45

February 17th, 2012 by

The latest press release form the Information Commissioner’s Office (ICO), dated 15 February 2012, explains how Cheshire East Council has been ordered to pay a monetary penalty of £80,000 following a breach of the data protection act (DPA) in May 2011.

You can read the full details of the breach on the ICO’s website and as a quick summary here’s what happened:

A council employee was asked to contact the local voluntary sector  co-ordinator to alert local voluntary workers to a police force’s concerns about an individual who was working in the area.

A series of blunders:

Failure 1 -  the local voluntary sector co-ordinator didn’t have an appropriate email account. How had they been communicating prior to this data breach???

Failure 2 - the council employee that was asked to contact the co-ordinator hadn’t had sufficient DPA awareness training and as a result, sent the email to the co-ordinators personal email account.

Failure 3 - the email, which contained the name and an alleged alias for the individual as well as information about the concerns the police had about him, was then forwarded by the co-ordinator to 100 intended recipients.

Failure 4 - the highly sensitive nature of the information contained in the email, and the need to restrict its circulation, wasn’t made clear to all recipients.

How this £80,000 fine could have been avoided for just £45:

The ICO have pointed out that Cheshire East Council failed to provide this particular employee with adequate data protection training.  What are the chances that this employee is not alone?

All members of staff that are involved with processing personal information as part of their daily job should undergo DPA awareness training and For a maximum outlay of £45 per head, Cheshire East Council could have avoided this data breach and avoided the £80,000 fine. 

The IT Governance Data Protection Awareness e-Learning course can be used as part of an induction process for new employees and as part of a  refresher programme for existing employees.

Having completed the 30-minute course, students can take a 20-question test. Students have the opportunity to re-take this test until the pass mark (75%) is achieved. An online Certificate of Achievement is issued to all students who pass the test which is clear evidence of adequate DPA training.

Find out more about the Data Protection Awareness e-Learning course, and safeguard your orgainsation today!