Posts Tagged ‘ISMS’

A Manager’s Guide to Data Security – Useful, Practical & Pragmatic

January 12th, 2012 by

“An essential reference work for information security professionals”
Milo Doyle, Head of Information Security, EBS Building Society

Read THE practical manual on data and information security:

  • Written in a useful, practical, pragmatic and non-technical style.
  • Provides a rigorous approach to implementing an Information Security Management System (ISMS).
  • Web-enabled to keep you up-to-date with key changes to the content of the book.
  • Is the Open University post-graduate information security text book

Read more here >>

IT Governance: A Manager's Guide to Data Security and ISO 27001 / ISO 27002, Fourth Edition IT Governance: A Manager’s Guide to Data Security and ISO 27001 / ISO 27002, Fourth Edition
by Alan Calder

Price: €57.95

Learn more

Buy Now

Watch Alan Calder review the book here, or for an alternate version on how practical this book really is, view this light-hearted version here >>

     

All aspects of data security / information security are covered including viruses, hackers, online fraud, privacy regulations, computer misuse, investigatory powers etc. It details how to design, implement and deliver an ISMS that complies with ISO 27001.

IT Governance: A Manager’s Guide to Data Security and ISO 27001/ISO 27002, 4th edition, has been updated taking into account all the latest changes in data security / information security. In addition, the book is Web-enabled, giving you access to the latest changes to the guidance contained in the book.

Read more here >>

Comply with ISO 27001 and reap the benefits

January 10th, 2012 by

ISO 27001 is the international best practise for an Information Security Management System (ISMS). Complying with the new Indian data privacy law is a must for all organisations that collect sensitive information. Organisations that become ISO 27001 certified, are deemed to be in full compliance with this law. Following the requirements of this standard will not only help you meet the obligations of the new Indian data privacy law, but will also protect your business against cyber threats and receive return on investments.

Comply with ISO 27001 by using the ISO 27001 (ISO/IEC 27001) ISMS Requirements. These can be employed by all types of organisations and ensures the selection of adequate and proportionate security controls that protect information assets and give confidence to interested parties.

Download these essential requirements today >>

ISO 27001 (ISO/IEC 27001) ISMS Requirements (Download) ISO 27001 (ISO/IEC 27001) ISMS Requirements (Download)
Price: $30.00

Learn more

Buy Now

     

What is ISO 27002?

ISO 27002 establishes guidelines and general principles for initiating, implementing, maintaining, and improving information security management in an organisation. ISO 27002 is a code of practice for information security, outlining potential controls and mechanisms which may be implemented subject to the guidance provided in ISO 27001.

This code of practice supports the implementation of ISO 27001 and helps organisations comply with new Data Privacy Regulations.

Download this code of practice today >>

ISO 27002 (ISO/IEC 27002) Code of Practice for ISM (Download)

Passwords at global intelligence company were ‘too weak’

January 10th, 2012 by

The Internet security passwords at global intelligence company, Stratfor, were ‘too weak’ claims researchers at Utah Valley University.

Stratfor (aka Stategic Forecasting) was hacked shortly before Christmas by well-known cyber gang, Anonymous. The firewall systems were broken into and subscribers of Strafor’s details data was posted online for all to see. What makes this case so unique, is that Stratfor provides analysis of data security issues, holding sensitive data regarding the online security industry.

Utah Valley University analysed the stolen data, only to find that security measures such as username and passwords were not secure enough to ward off hackers. Subscribers to Strafor were put at risk as details of their accounts and card numbers were published by Anonymous.

IT director and professor for Utah Valley University, Kevin Young, said that Stratfor “should have known better” in order to protect themselves against such a thing happening.

So if a data security company can’t use strong passwords, then what hope does this leave for the rest of us? 

Make sure you and the rest of your staff use strong passwords to protect your confidential data. Take the ITG E-Learning Course: Information Security & ISO27001 Staff Awareness. The contents of this course covers these key points:

  • What has Information Security got to do with you?
  • Where does your organisation fit in?
  • Definitions: what is Information Security?
  • Could this happen to you? (Scenarios and follow up questions).
  • Information Security at work
  • Clear desk and screen
  • Passwords
  • Information classification
  • Intellectual property
  • Security incidents
  • Business continuity
  • Important documentation, with links to key policies and procedures
  • Information Security & ISO27001 Staff Awareness – Online Test & Certificate

Make sure you and your staff are aware of information security and alert to the threats it brings.

Take this e-Learning course today >>>

 

What will protect you from IT Security threats?

January 4th, 2012 by

IT security is an issue that all organisations must address. Consider these facts:

  • Modern businesses and organisations must protect themselves from the growing threat of cyber attacks and cyber crime
  • Cyber security is a senior management issue not just an IT issue
  • Protection of your critical assets should cover systems, networks and work practices
  • Ensuring staff are trained in cyber security is as important as having robust system defences
  • Effective and robust cyber security can help you win new business, improve customer confidence and reduce IT expenditure

So, how do you ensure you have robust, effective and proportional cyber security measures in place for your organisation? The answer is of course, ISO27001.

But what is ISO27001?

  • ISO27001 is the new, world leadingcyber security standard
  • ISO27001 is the onlyinternationally recognised cyber security standard, which an organisation can be certified against
  • ISO27001 providesa framework for creating a cyber security management system
  • ISO27001 will help you identifythe risks to your organisation and build defences to protect yourself from them
  • ISO27001 will help you create documentation, systems and work practices to ensure the continual protection against cyber crime and cyber attack

IT security and ISO27001 can seem like a daunting issue to tackle within an organisation. It is complex and an ISO27001 project is not something that can be achieved overnight. ISO27001 is a relatively new international standard, however it is quickly becoming the benchmark for cyber security defences within organisations. More and more organisations are adopting ISO27001 and reaping the business benefits of being aligned to the standard.

You can find more information about ISO27001, its benefits and a free white paper here >>>

However the best place to start building your knowledge of ISO27001 is with this easy to read pocket guide: An Introduction to Information Security and ISO27001

An Introduction to Information Security and ISO27001 An Introduction to Information Security and ISO27001
by Steve G. Watkins

Price: €11.95

Learn more

Buy Now

     

Who can protect you from cyber crime and cyber attacks? Would ISO27001 please stand up

January 4th, 2012 by

Cyber security is an issue that all organizations must address. Consider these facts:

  • Modern businesses and organizations must protect themselves from the growing threat of cyber attacks and cyber crime
  • Cyber security is a senior management issue not just an IT issue
  • Protection of your critical assets should cover systems, networks and work practices
  • Ensuring staff are trained in cyber security is as important as having robust system defences
  • Effective and robust cyber security can help you win new business, improve customer confidence and reduce IT expenditure

So, how do you ensure you have robust, effective and proportional cyber security for your organization? Would ISO27001 please stand up.

But what is ISO27001?

  • ISO27001 is the new, world leading cyber security standard
  • ISO27001 is the only internationally recognised cyber security standard, which an organization can be certified against
  • ISO27001 provides a framework for creating a cyber security management system
  • ISO27001 will help you identify the risks to your organisation and build defences to protect yourself from them
  • ISO27001 will help you create documentation, systems and work practices to ensure the continual protection against cyber crime and cyber attack

Cyber security and ISO27001 can seem like a daunting issue to tackle within an organization. It is complex and an ISO27001 project is not something that can be achieved overnight. ISO27001 is a relatively new international standard, however it is quickly becoming the benchmark for cyber security defences within organizations. More and more organizations are adopting ISO27001 and reaping the business benefits of being aligned to the standard.

You can find more information about ISO27001, its benefits and a free white paper here >>>

However the best place to start building your knowledge of ISO27001 is with this easy to read pocket guide: An Introduction to Information Security and ISO27001

An Introduction to Information Security and ISO 27001 An Introduction to Information Security and ISO 27001
by Steve G Watkins

RRP: $19.95
Price: $14.95
You Save: $5.00

Learn more

Buy Now

     

Start understanding ISO27001 and cyber security today >>>

10 biggest cyber threats of 2011

January 4th, 2012 by

2011 saw a vast growth in the number of malware attacks on businesses and individuals. Hackers are now at a point where they can “wreak havok and access the best-kept secrets of organisations without ever leaving their living-rooms”. From phishing scams, to the Sony hack, 2011 has seen the worst of all cyber attacks. Millions of people’s data has been compromised around the world: hackers have made millions, whilst companies have lost millions. So, will 2012 see a repeat of last year? Or will we clamp down on cyber crime once and for all?

We here at IT Governance Ltd have picked the bad and the very bad to show you just what a year it’s been in cyberspace….

1. Sony PlayStation hack

Now this really was the worst of the worst – names, addresses and card details were stolen from around 77 million people who had accounts with the PlayStation Network (PSN).

2. Student loan phishing scam

Students across the UK mistakenly handed over access to their bank details after receiving an email asking them to confirm their details. Anywhere between £1,000 and £5,000 was stolen from each student who gave access.

3. Android apps

22 apps were removed from the android market by Google after it was discovered they contained fradulant software. The apps tricked users into sending premium text messages.

4. RIM hack

Blackberry’s blog was hacked after the London riots, warning Blackberry not to assist the police.

5. Local council fined £130,000 for breach of DPA

Powys Council, England, was fined £130,000 after the details of a child protection case were sent to the wrong person. This was one of the largest fines the ICO have actioned against a council. Read more >>

6. WikiLeaks

WikiLeaks was responsible for releasing top secret information about governments across the world on its website.

7. NHS Breach

Lulzsec hacked the NHS, alerting them that their information security management system was inadequate. However, they put on the “white hat” approach, publicizing the hack but not revealing any compromising information.

8. Gmail phishing scam

Chinese identity thieves used ‘spear phishing’ tactics to take over hundreds of Gmail accounts, including those belonging to senior officials and military personnel.

9. Epsilon data breach

Epsilon, the email communication giant was hacked in March 2011, where customer email lists were stolen from at least 26 different companies.

10. RSA attack

One of the most high-profile breaches of 2011 involved the world’s most-used two-factor authentication systems. Hackers stole information relating to RSA’s SecurID system, by mimicking RSA naming conventions to avoid detection. What was so unique about this case, was that only one attack on an RSA customer was ever reported, showing that the counter-actions RSA took were extremely effective.

Source: Security News Daily, Information Week and Real Business.

The lesson to take away from these hacks and breaches is that companies and individuals alike need to be educated on cyber issues. There needs to be an understanding of what to look out for, what to click and what not to click, who to give your details to and who not to, and to generally be alert, rather than sticking our heads in the sand.

Education will help combat cyber issues and prevent repeat attacks occurring in 2012.

We have a number of staff awareness training courses available at IT Governance, covering DPA, Information Security and ISO 27001 and PCI DSS training. These are extremely effective and affordable, considering no travelling or other course attendance costs are incurred, as learners can study from their desk in their spare time.

Book your e-Learning course today >>

CERT India finds ‘Kim Jong-Il’ spam

January 3rd, 2012 by

Indian computer security analysts have found a vicious malware virus streaming into its cyberspace, in the name of the late North Korean leader Kim Jong-Il. The said file, if opened, will hack and crash vulnerable e-mail addresses.

The Indian Computer Emergency Response Team (CERT-In) detected and alerted internet users to the spam mails that carried a fake name of; ‘brief_introduction_of_kim_jong_Ill_pdf.pdf’. They are currently asking all government and other IP addresses to not click on the link as it may lead to a loss of valuable data.

CERT-In clarified; “The said pdf file is exploiting vulnerabilities in Adobe reader and Acrobat, that once successfully exploited leads to remote code execution in the victim system,”

Source: The Times of India

Make sure your emails remain safe on the Internet with E-mail Security: A Pocket Guide. This guide will help you use email clients to improve security, preserve confidentiality, protect your company’s reputation and defend your business from an attack. This pocket guides is available for you to download today.

Read more about E-mail Security: A Pocket Guide >>

One and only toolkit offer expires soon!

December 19th, 2011 by
 

 

Hurry, this special offer expires soon! Order BS25999 BCMS Implementation Toolkit before 23rd December and receive ICT Strategy Toolkit absolutely free!

BS25999 BCMS Implementation Toolkit contains all the templates and tools that will enable you to quickly and effectively implement a BCMS in line with BS25999.

 

No 4 ISO27001 Complete ISMS Documentation Toolkit. (Download & Manager's Guide) BS25999 BCMS Implementation Toolkit (Download)

Price: Rs 17,224.58

Plus, free ICT Strategy Toolkit when you order before 23rd December.

Learn more

Buy Now

More offers like this:

No 4 ISO27001 Complete ISMS Documentation Toolkit
No 4 ISO27001 Complete ISMS Documentation Toolkit

Learn more

Buy Now

 

 

vsRisk™ - The Cybersecurity Risk Assessment Tool
 

vsRisk™ – The Cybersecurity Risk Assessment Tool

Learn more

Buy Now

Do Your Part – Be Internet Security Smart!

December 15th, 2011 by

History has taught us: never underestimate the amount of money, time, and effort someone will expend to thwart a security system. It’s always better to assume the worst. Assume your adversaries are better than they are. Assume science and technology will soon be able to do things they cannot yet. Give yourself a margin for error. Give yourself more security than you need today. When the unexpected happens, you’ll be glad you did. – Bruce Schneier

Realise the benefits of Internet technologies, while ensuring your company is protected from the associated risks.

If you want to make the Internet work for your business, you need to take the right precautions – Buy this book today! >>

Cyber Risks for Business Professionals: A Management Guide Cyber Risks for Business Professionals: A Management Guide
by Rupert Kendrick

Price: €47.95

Learn more

Buy Now

 

Cyber Risks for Business Professionals: A Management Guide is a general guide to the origins of cyber risks and to developing suitable strategies for their management. It provides a breakdown of the main risks involved and shows you how to manage them. Covering the relevant legislation on information security and data protection, the author combines his legal expertise with a solid, practical grasp of the latest developments in IT to offer a comprehensive overview of a highly complex subject.

Rupert Kendrick was formerly a practising solicitor. More recently he has been a director in a risk management consultancy, addressing legal IT and Internet risk issues. Rupert Kendrick is the author of Outsourcing IT: A Governance Guide, also published by IT Governance.

Buy this book today! >>

More to explore:

CyberWar, CyberTerror, CyberCrime
CyberWar, CyberTerror, CyberCrime
by by Julie E. Mehan

Learn more

Buy Now

Managing Information Security Breaches
Managing Information Security Breaches
by Michael Krausz

Learn more

Buy Now

How to Survive a Data Breach
How to Survive a Data Breach
by Stewart Mitchell

Learn more

Buy Now

Special Offer: Find your route to a cost-effective and ISO27001 compliant ISMS

December 12th, 2011 by

Used together, the No 3 ISO 27001 Comprehensive ISMS toolkit and the ICT Strategy toolkit will help you:

  • Accelerate your ISO 27001 project
  • Develop an ISO27001-compliant Information Security Management System (ISMS)
  • Create an ICT strategy
  • Cut costs
  • Control risks

Until the 23rd December 2011, the ICT strategy toolkit is FREE when you buy the No 3 ISO27001 Comprehensive ISMS toolkit!

These toolkits go hand in hand together when implementing a cost-effective and ISO 27001 compliant ISMS.

Accelerate your ISO27001 project with the No 3 toolkit, and get the ICT Strategy toolkit absolutely free when you order before 23rd December >>

No 3 ISO27001 Comprehensive ISMS Toolkit No 3 ISO27001 Comprehensive ISMS Toolkit

RRP: £1931.90
Price: £1795.00
You Save: £136.90

Learn more

Buy Now

  Order this toolkit before Friday 23rd December and receive the ICT Strategy toolkit absolutely free!  
ICT Strategy Toolkit
ICT Strategy Toolkit
FREE with this best-selling toolkit until December 23rd 2011!

Until the 23rd December 2011, the ICT strategy toolkit is FREE when you buy the No 3 ISO27001 Comprehensive ISMS toolkit!