Home > Risk management: Implementation of baseline controls
Learning Guide:
EMAIL THIS LICENSING & REPRINTS

Risk management: Implementation of baseline controls

30 Aug 2006 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Layer on baseline controls in accordance with CIA information ratings. This step ties the organization's business risks into information security controls. Many organizations are challenged with regulatory compliance and implementation of security best practices. Do not lose track of the big picture, controls are meant to insulate the business from unacceptable risk. The simple process of applying controls based upon data sensitivity and impact ratings will address most compliance concerns. Any deviation from baseline controls should require a formal exception approved by information security management and the business.


INSIDER THREAT MANAGEMENT GUIDE

  Introduction: Insider threat management
  Data organization and impact analysis
  Baseline management and control
  Implementation of baseline control
  Risk management audit
  Risk management references


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Risk Assessment and Analysis
PCI is about eliminating data, not securing it, former QSA says.
Security visualization helps make log files work
Unified communications trigger data leakage dangers, survey finds
CIO role could shift toward data quality, says IBM group
Security data lapses hamper researchers
Panel: IT governance, risk and compliance program helps reduce expenses
Like MLB scouts, IT security pros are turning to metrics
Google shares struggle to manage security complexities
GRC Tools Help Manage Regulations
Interview: Financial Services CISO David Pollino

Insider Threats
Societe Generale bolsters internal controls, discovers second insider
Information security book excerpts and reviews
I am concerned that a former employee will utilize corporate information in a malicious way.
Security pros focused on internal threat, training
Reasearch on Coding Backdoors Presents Ugly Picture
Deloitte survey finds overconfidence, lack of planning on security
Data loss prevention from the inside out
Insider dangers
Survey finds access control problems at many firms
Societe Generale: A cautionary tale of insider threats

Creating and Managing Information Security Policies
IT security not valued at many firms, study finds
Sound compliance policies, practices reduce legal costs
Exploring Microsoft's Network Access Protection policy options
IAM best practices for employees with varying degrees of access to the same computer
How to avoid DLP implementation pitfalls
What's your advice for getting other business units to contribute to crafting an effective information security policy?
Security Awareness Training Essential Part of Infosec Program
Is it necessary to grant a full administrative privileges to a security administrator?
How to lock down instant messaging in the enterprise
Worst practices: Bad security incidents to avoid
Creating and Managing Information Security Policies Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
risk analysis  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
Find Security Channel Research for Resellers and Partners
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts