Recently I was asked if I could provide a few pointers to help in developing a risk assessment process for an organization. I thought I would share my response. First, I would like to draw your attention to the mind map image over to the left of this text. The mind map [...]
Read Full Post »
Revolution
On this 4th of July, I find myself wondering if a revolution is about to occur in the information security arena. Is the policy based compliance model going to be overthrown by the risk-based protection model? What are the ramifications? Are most CIOs aware or even ready for such change?
Technological Upheaval
Ground [...]
Read Full Post »
Posted in COBIT, NIST on Feb 3rd, 2008
“Information security provides the management processes, technology and assurance to allow businesses’ management to ensure business transactions can be trusted; ensure IT services are usable and can appropriately resist and recover from failure due to error, deliberate attacks or disaster; and ensure critical confidential information is withheld from those who should not have access to [...]
Read Full Post »