Posts Tagged ‘Information Security’

It pays to invest in cyber security

April 10th, 2012 by

Buy the No 3 ISO27001 Comprehensive ISMS Toolkit before 20th April 2012 and get a free Cyber Security Self Assessment Tool.

As budgets are agreed for the new financial year you need to ensure that you are investing in cyber security. Not only will robust and effective cyber security protect your business, clients and reputation, it will also help you win new business in this ever increasingly cyber security conscious economy.

All businesses should be creating an information security management system aligned with ISO27001, the world’s cyber security standard.

The No 3 ISO27001 Comprehensive ISMS Toolkit contains all the specialist books, templates and guidance to enable you to quickly and effectively implement an ISMS in line with ISO27001.

No 3 ISO27001 ISMS Toolkit No 3 ISO27001 Comprehensive ISMS Toolkit

RRP: £1,931.90
Price: £1,795
You Save: £136.90

Learn more

Buy Now

     

Buy the No 3 ISO27001 Comprehensive ISMS Toolkit toolkit before 20th April 2012 and get a free Cyber Security Self Assessment Tool.

Theresa, Nick, Big Dave & George Orwell… Can I Look At Your Emails…

April 4th, 2012 by

If there is one thing our Government does well its courting controversy. Couple that with how there seems to be a constant disregard for how their half baked proposals will inflame the public and you have another recipe for political disaster, or at least a U-turn, for now.

Yes, I’m talking about the powers to monitor our web activity, emails, phone calls and visits to the lav. Last week Theresa May, writing in The Sun, started the fire when she claimed the Government needed powers to monitor every aspect of our digital lives in order to help the police and security services track criminals, terrorists and presumably any MP downloading porn during work hours.

Naturally this inflamed the public, civil liberty groups and even some MP’s. Nick Clegg moved quickly to put the fire out stating that such legislation would be published only as a draft and would be omitted from the Queen’s Speech. Comments were made about not wanting to rush anything through parliament and big Dave stated: “It’s essential we get this right. Yes to keeping up with modern technology. No to a snoopers charter.” Phew.

Apparently Whitehall insiders believe the policy is now in disarray. But let’s not be hasty, the Government usually finds a way to re-package a plan and send it back out again. I believe such monitoring already happens in America, I’ll receive letters if that not true, but I believe it does. So, why not here the Government thought?

As I stated Theresa started the fire when she wrote in The Sun last week… “Looking at who a suspect talks to can lead police to other criminals. Whole pedophile rings, criminal conspiracies and terrorist plots can then be smashed.”
She continued…”currently online communication by criminals can’t always be tracked. That’s why the Government is proposing to help the police stay one step ahead of the criminals.”

In affect Mrs. May was proposing that internet providers store billions of pieces of data for up to two years; the Home Office estimated the scheme would cost around £2 billion over 10 years. Mrs. May eased the fears of the man on the street by stating that ‘ordinary people’ would not be targeted, and it is presumed that warrants would be required to access such data.

However, when we see other countries around the world fighting for the democracy we enjoy in the UK, doesn’t this announcement leave a somewhat sour taste in the mouth. Synergies to Orwell’s 1984 may be somewhat premature, but it’s easy to see why comparisons are being drawn. Is mass surveillance on a country wide scale just a vote away in the commons? As a society have we become so hidden behind our digital selves that we would stand back and let this happen? Albeit with the mandatory signing of an e- petition (remember they’ll probably store your details in case they need them later on down the road).

Indeed, earlier this week previously confidential papers from the Information Commissioner Christopher Graham were released in which he raised his concerns. In storing so much data Graham commented that this would be a “step change in the relationship between the citizen and the state”.

The civil liberties group Big Brother Watch has naturally been disgusted by these events and has started an e-petition (told you), twitter topics and online campaigns.

For now though the deadly duo of Nick and Dave have poured a little water on the surveillance fire. But it is still smoking. The monitoring of the internet, digital devices, security and the freedom and privacy of the individual are huge issues that are not going to go away in the digital age.

There is no doubt that the police and security services are well behind the curve in how they use technology to help them catch and prevent criminal and terrorist activities. But there is also no denying that there is a raging force that is the individual’s right to their own privacy. Whether though, if it came to it, as a society, would we make too much of a fuss if such a piece of legislation came into operation, is another matter. ..

Global Payments suffers the wrath of a data breach

April 3rd, 2012 by

Over the weekend, you may have heard of Global Payments’ data breach, which caused 1.5 million credit card accounts to be compromised.

Global Payments, which processes payments for fims such as Visa, Mastercard and American Express admitted that thieves had accessed card account numbers, expiration data and security codes.

As a result of the data breach, Global Payments has:

  • Suffered an 12% price drop in shares
  • Lost one of its most important customers; Visa promptly dropped Global Payments from its list of approved vendors and Global Payments is expecting Mastercard to do the same

So in less than 4 days, the US payment processor has suffered a significant loss to their company, including vital and powerful customers, a drop in share prices and significant brand damage.

How easy do you think it will be for Global Payments to win back contracts with Visa and possibly Mastercard? Will they ever regain trust from both customers and clients?

It looks unlikely, but they can always hope. Global Payments Chief Executive Paul Garcia has pledged to spend more on security, but is it all a little too late?

We don’t just tell you this stuff to scare you, they’re real facts that are happening to real companies throughout the world.

In the UK, all organisations must comply with the Data Protection Act and every organisation that stores, transmits or processes card holder data must comply with the Payment Card Industry Data Security Standard (PCI DSS).

Get your company up to scratch with DPA, PCI DSS and Information Security (ISO 27001) with specific training courses >>

Source: BBC

Specially designed package for Cybersecurity skills

April 3rd, 2012 by

Gain the skills required to tackle Cybersecurity using the international best practice standard, ISO 27001. This specially priced accredited combination package will take you from foundation to advanced in just 4 days!

ISO 27001 Information Security Training Package ISO 27001 Information Security Training Package
Choose the dates to suite your projectRRP: £2,209.00
Price: £1,994
You Save:£295.00

Learn more

Buy Now

   

This specially priced package includes attendance at both the

Watch out for our Early bird discount and last minute savings. If your diary means you need to mix and match dates and locations, we can help you do this.

Book Online today!

Accelerate your ISO27001 project with this March offer!

March 26th, 2012 by

Accelerate your ISO27001 project with the Standalone ISO27001 ISMS Documentation Toolkit, now with 10% off until 30th March.

“Using the templates, was the only way that we could deliver a 1st edition ISMS in under 6 months. Our deliverable was a work in progress but miles ahead of where they would have been without the templates.”
Tim Moreton, President, Moreton & Co., airlinetechnology.net

This toolkit contains all the procedure templates and documents you need to simplify your progress to ISO27001 certification, whilst saving time and money.

Standalone ISO27001 ISMS Documentation Toolkit Standalone ISO27001 ISMS Documentation Toolkit

Price: €489.00

Learn more

Buy Now

Special offer: Add the voucher code marchoffer at the checkout and get 10% off any toolkit!
Valid until Friday 30th March only!

     

ISO27001 is the best-practice specification that helps businesses and organisations throughout the world to develop a best-in-class Information Security Management System (ISMS).

Accelerate your ISO27001 project with this Toolkit, now with 10% off until 30th March>>

Useful Links:

More to explore:

21st Century Chinese Cyberwarfare
21st Century Chinese Cyberwarfare

Learn more

Buy Now

Nine Steps to Success: an ISO 27001 Implementation Overview
Nine Steps to Success: an ISO 27001 Implementation Overview

Learn more

Buy Now

The Case for ISO 27001
The Case for ISO 27001

Learn more

Buy Now

Information Security Awareness: The What, The Why and You

March 26th, 2012 by

Q:  Your CEO phones for help in dealing with a major malware intrusion and asks for your password. Should you disclose it?

If you or your employees can’t answer this question, your organisation may be in trouble…..

This is just one of hundreds of situations and scenarios employees can be confronted with at or outside work. The ability for staff (or the lack of it) to behave adequately in situations (like the above) can have a serious impact on your business.

Raising information security awareness is not an easy task. It has to be supported by visible leadership and clear organisational values.  People will always make mistakes and create security incidents. Some may be tricked and manipulated by external influences and a few disgruntled, and possibly dishonest employees may cause considerable loss and damage to your company. Raising awareness will make your employees more alert to threats. Aligning your requirements with the values and culture of your organisation may turn even those disgruntled employees into followers.

Why should you bother raising information security awareness amongst staff?

  • Members of staff are a key part of ensuring that you protect the crucial intellectual assets of your organisation, namely your confidential information, relationships and reputation.
  • Staff who don’t understand what behaviour is expected of them may be putting your information and business at risk.
  • Poorly trained front-line staff may mean the organisation is vulnerable to phishing, pharming and social engineering attacks
  • Poorly trained data handling staff may mean cause breaches against the Data Protection Act (DPA) – potentially leading to £500k fines
  • Poorly trained HR, supervisory and other management staff may mean significant levels of an insider attack. (Did you know… insider attacks are responsible for perhaps half of all breaches).

What can you do?

  • Implement an integrated training policy relevant to your organisation to support the desired culture
  • Constantly update and remind your staff of the importance of information security
  • Train staff without them realising they are being trained – create fun and interactive ways of bringing your messages across
  • Engagement is key – getting employees engaged can achieve more than enforcing just a policy

Why should you use e-learning to raise information security awareness?

  • In a very short time employees will be able to get an overview of the relevant topic (i.e. information security, data protection, compliance etc.), and why it is important
  • They will be able to apply this knowledge to protect their own personal information as well as the organisation’s information assets.
  • There are no travel or other course attendance costs.
  • It is flexible and convenient – employees can study from their desk top and in their spare time.
  • It is fun – e-learning uses interactive techniques and it doesn’t feel like work; at the same time it is effective, enabling employees to understand and remember things easily.

IT Governance has a range of e-learning courses available to help you raise awareness amongst your staff on the subject of information security.

For only £45 you can buy your e-learning single user licence from IT Governance now or multi-user licenses for a discounted price, which covers all types of information security training!

A customisable courseware option is available for bigger organisations that are buying a multi-user license. Call 0845 070 1750 to discuss your options now!

The IT Governance e-learning courses have already been embraced by clients as an effective tool for educating users and for meeting compliance requirements. They are designed to increase employees’ awareness of the relevant Standards requirements and thereby reduce the organisation’s liability due to security failures.

The available e-learning courses are:

SME’s are at risk of cyber attack – start building your defences today

March 21st, 2012 by

The recent Symantec Threat Awareness Survey uncovered that over 50% of the 1,900 SME’s interviewed for the poll thought that they were immune to cyber crime because they were too small.

However, Symantec’s report found that since 2010 40% of all attacks were on SME’s. Ross Walker, Symantec director of small business commented “Hackers are going after ‘low hanging fruits’, these are the companies who are less security aware and do not have the proper defences in place.”

The best way to build robust and effective cyber defences is by implementing ISO27001, the world’s cyber security standard. The easiest way to do this is with the No 3 Comprehensive ISMS ISO27001 Toolkit – which contains all the tools, templates and guidance to implement your own ISO27001 project.

Until the end of March this toolkit comes with a free cyber security assessment tool!

 

No 3 ISO27001 Comprehenisve ISO27001 ISMS Toolkit No 3 ISO27001 Comprehenisve ISO27001 ISMS Toolkit

RRP: £1931.90
Price: £1795.00
You Save:£136.90

Learn more

Buy Now

     

Achieving ISO 27001 certification is the best way for an organisation to protect its information assets, mitigate the risk of Cyber attack (and other forms of data breach), and to win new business.

The No 3 Toolkit will accelerate your ISO27001 project, provide you with essential resources, documentation templates and includes our unique 12 month drafting support

Take cyber security seriously.

Order the No 3 Toolkit today >>>

Effectively mitigate information security risks within your business

March 21st, 2012 by

With ISO 27005:2011 you will be able to implement information security into your business, via a risk management approach. This standard provides guidelines on Information Security Risk Management (ISRM), enabling you to effectively mitigate information security risks.

This standard is applicable to any organisation, regardless of size or type. Read Alan Calder’s, (CEO of IT Governance) thoughts on this new standard:

  • “It is a better written, more coherent standard”
  • “It is aligned with the risk management standard ISO 31000, which makes it easier to integrate enterprise risk management approaches with information security risk management”
  • “It provides good, practical guidance on carrying out the risk assessment required by ISO 27001, together with clear guidance on risk scales”
  • “It has good guidance on threats, vulnerabilities, likelihoods and impacts.”

Read more about this standard>>

ISO27005 (ISO 27005) ISRMS ISO27005 (ISO 27005) ISRMS

Price: €114.00

Learn more

Buy Now

     

Fully aligned with the International Standard for risk management, ISO 31000, and using common concepts conveyed from ISO 27001 and ISO 27002, this standard will provide you with the guidelines to effectively mitigate information security risks within your business.

Buy this standard today to effectively mitigate information security risks >>

More to explore:

vsRisk - ISO 27001: 2005 Compliant Information Security Risk Assessment Tool
vsRisk – ISO 27001: 2005 Compliant Information Security Risk Assessment Tool

Learn more

Buy Now

ISO31000 (ISO 31000) Risk Management Guidelines
ISO31000 (ISO 31000) Risk Management Guidelines

Learn more

Buy Now

ISO27001 ISMS Requirements
ISO27001 ISMS Requirements

Learn more

Buy Now

This book is like having a €200 per hour consultant by your side

March 19th, 2012 by

Whether you’ve just begun, or part-way through implementing ISO 27001, Nine Steps to Success: an ISO27001 Implementation Overview is an ideal guide to read.

‘It’s like having a £200/hr consultant at your elbow as you consider the aspects of gaining management support, planning, scoping, communication, etc…’
Thomas F. Witwicki

This book covers nine critical steps you will undertake to successfully achieve ISO 27001 certification. So if you are about to tackle, or are tackling ISO 27001, then this the perfect stepping-stone to success.

Buy your copy today>>

Nine Steps to Success: an ISO 27001 Implementation Overview Nine Steps to Success: an ISO 27001 Implementation Overview
by Alan Calder

Price: €35.95

Learn more

Buy Now

     

Buy your copt today >>

More to explore:

The Case for ISO 27001
The Case for ISO 27001

Learn more

Buy Now

Standalone ISO27001 ISMS Documentation Toolkit
Standalone ISO27001 ISMS Documentation Toolkit

Learn more

Buy Now

ISO 27001 (ISO/IEC 27001) ISMS Requirements
ISO 27001 (ISO/IEC 27001) ISMS Requirements

Learn more

Buy Now

Use your remaining budget to tackle cyber security

March 19th, 2012 by

Cyber security is a high priority in boardrooms right now and ISO 27001 is the only management system standard that will enable you to demonstrate to the board that you are taking this issue seriously.

At IT Governance, we’re committed to helping organisations to mitigate Cybersecurity risks and budget more effectively for the future.

As budgets are agreed and plans for the next financial year are drawn up, savvy managers will be looking to get maximum value from their current budget and will take advantage of advance-buy offers in order to maximise the return on their investment in the training and resources required for the coming months.

We have the end-to-end solution for all your information security, IT governance, risk management and compliance needs.

Our comprehensive training course catalogue can help you and your organisation compete and survive in the insecure 21st Century. Many organisations have taken advantage of our Early Bird pricing and last minute discounts.

Have you seen our special, multi-booking, extra-value discount? – Book one or more place on all your preferred courses (from now until 31 December 2012) with a cumulative value of £10k or more and we’ll immediately throw in a £1k rebate! We’ve only got so many places available at this special price and the offer is only available until 27th March 2012, so you need to act fast!

Our training courses offer delegates a fantastic range of benefitsread what previous attendees have said here.

Did you also know we offer prefessional services? We have a full range of consultancy services in IT governance, risk and compliance. With over 10 years of practical experience, IT Governance can provide consultancy services for any organisation, anywhere in the world. To talk to someone in our consultancy team call +44 845 070 1750.

We also have a full range of documentation toolkits and a wide range of books and pocket guides that are ideal for organisations looking for a do-it-yourself approach to implementing management system standards.

We’ve also removed risk: because we know things change, you can change delegate names on courses right up to a week before the course start date. You don’t even have to specify a delegate at this time. Choose between a wide range of courses that suit your requirements and save £1,000 or more in the process. Talk to us today.

0845 070 1750

See the ITG Training catalogue now >>