The ISACA Security Management Conference (SMC2007) is "happening" Nov 6th and 7th.
1. Our various speakers are leaders in improving security practices and have been involved in the development of extensive security related guidance.
2. See below for an extensive summary of just some of the resources our various speakers have been involved in publishing.
3. Attend the SMC2007 conference and hear the various views and opinions of our speakers and as important be able to discuss first hand your issues, challenges,
and questions.
Hope to see you there.
Register today to reserve your space (We may sell this one out).
Regards.
Dan Swanson
SMC2007 Conference Chair
__________________________________________________________
Setting the Standard in Security Management:
- It’s not a matter of if…it’s a matter of when!
__________________________________________________________
Join ISACA® Winnipeg Chapter and IPAM on November 6th & 7th, 2007 at the Radisson Downtown (http://www.radisson.com/winnipegca), in Winnipeg, Manitoba, Canada.
The 2007 Conference details are at http://www.isaca-wpg.org/SMC2007/program.htm
Register for this two-day conference at www.isaca-wpg.org/SMC2007
Members - $425.00 Non-members - $575.00
(A reception from 5:00pm to 7:30pm will follow the conference on both nights)
Info on Winnipeg is available at - http://www.destinationwinnipeg.ca/
__________________________________________________________
Leading Resources to support your Information Security improvement efforts
__________________________________________________________
The Computer Security Division (CSD) of the National Institute of Standards and Technology (NIST), including the Federal Information Security Management Act (FISMA) library.
The mission of NIST's Computer Security Division is to improve information systems security by:
Raising awareness of IT risks, vulnerabilities and protection requirements, particularly for new and emerging technologies;
Researching, studying, and advising agencies of IT vulnerabilities and devising techniques for the cost-effective security and privacy of sensitive Federal systems;
Developing standards, metrics, tests and validation programs:
to promote, measure, and validate security in systems and services
to educate consumers and
to establish minimum security requirements for Federal systems
Developing guidance to increase secure IT planning, implementation, management and operation.
http://csrc.nist.gov/
http://csrc.nist.gov/sec-cert/ca-library.html
Build Security In (BSI)
As part of the Software Assurance program, Build Security In (BSI) is a project of the Strategic Initiatives Branch of the National Cyber Security Division (NCSD) of the Department of Homeland Security (DHS). The Software Engineering Institute (SEI) was engaged by the NCSD to provide support in the Process and Technology focus areas of this initiative. The SEI team and other contributors develop and collect software assurance and software security information that helps software developers, architects, and security practitioners to create secure systems.
https://buildsecurityin.us-cert.gov/daisy/bsi/home.html
CERT®'s Resiliency Engineering Research
The cornerstone of their research is the development of the CERT® Resiliency Engineering Framework. The framework is the foundation for a process improvement approach to security and business continuity. It establishes an organization’s resiliency engineering process: a collection of essential capabilities that an organization performs to ensure that its important assets—people, information, technology, and facilities—stay productive in supporting business processes and services. The framework serves as a foundation from which an organization can measure its current competency, set improvement targets, and establish plans and actions to close any identified gaps. As a result, the organization repositions and repurposes its security and business continuity activities and takes on a process improvement mindset that helps to keep these activities productive in the long run.
http://www.cert.org/resiliency_engineering/
The Center for Internet Security (CIS) is a non-profit enterprise whose mission is to help Organizations reduce the risk of business and e-commerce disruptions resulting from inadequate technical security controls. CIS members develop and encourage the widespread use of security configuration benchmarks through a global consensus process involving participants from the public and private sectors. The practical CIS Benchmarks support available high level standards that deal with the "Why, Who, When, and Where" aspects of IT security by detailing "How" to secure an ever widening array of workstations, servers, network devices, and software applications in terms of technology specific controls. CIS Scoring Tools analyze and report system compliance with the technical control settings in the Benchmarks. The CIS Benchmarks and Scoring Tools are available for download free of charge.
http://www.cisecurity.org/index.html
Process Agnostic Navigational View
The process agnostic approach incorporates security into each basic phase of software development. The best practices and methods described are applicable to any and all development approaches as long as they result in the creation of software artifacts.
https://buildsecurityin.us-cert.gov/daisy/bsi/438.html
Governing for Enterprise Security Implementation Guide
This guidance is designed to help business leaders implement an effective program
to govern information technology (IT) and information security. http://www.cert.org/governance/ges.html
· Article 1: Characteristics of Effective Security Governance (pdf) · Article 2: Defining an Effective Enterprise Security Program (ESP) (pdf) · Article 3: Enterprise Security Governance Activities (pdf)
ISO27001 in North America ISO27001 is the new, international standard of information security best practice. With its origins in ISO17799 and BS7799, ISO27001 is providing comprehensive best-practice advice and guidance to private and public sector organizations around the world on how to design and implement an effective information security management system ('ISMS'). On this site, you can find out how an ISO27001 ISMS can help organizations meet their commercial and business needs for cost-effective information security while at the same meeting their information- related regulatory compliance objectives and positioning them for new and emerging regulations.
http://www.27001.com/default.aspx
The Defense-in-Depth Foundational Curriculum handbook discusses information assurance issues and how to address these at both organizational and technical levels. The handbook is written for students ranging from system administrators to CIOs who have some technical understanding of information systems.
http://www.cert.org/archive/pdf/Defense_ in_Depth092106.pdf
Guide 6: Managing and Auditing IT Vulnerabilities
The IIA has released its sixth guide in its Global Technology Audit Guide (GTAG®) series, Managing and Auditing IT Vulnerabilities. The 24-page guide was developed to help CAEs and internal auditors ask the right questions of IT security staff when assessing the effectiveness of their vulnerability management processes. The guide recommends specific management practices to help an organization achieve and sustain higher levels of effectiveness and efficiency and illustrates the differences between high- and low-performing vulnerability management efforts. http://www.theiia.org/guidance/technology/gtag/gtag6/
The (ISC)² 2007 Resource Guide for Today's Information Security Professional - Global Edition - provides the latest resources in educational references, year-long events listings and leading industry sponsors all in one handy downloadable reference guide.
https://www.isc2.org