In this resource guide get details, tips and resources on ISO 17799 and ISO/IEC 27002 certification, including auditing and compliance, standards, guidelines, implementation.
Is the Orange Book still relevant for assessing security controls?
06 Oct 2008 EXPERT ANSWER - Is the Orange Book still the be-all and end-all for assessing security controls in the enterprise? Security management expert Mike Rothman explains what happened to the Orange Book, and the Common Criteria for Information ...
Does SOX provision email archiving?
04 Aug 2008 EXPERT ANSWER - Although SOX may lack specificity regarding certain controls, it does have clear mandates for email retention.
COSO and COBIT: The value of compliance frameworks for SOX
25 Jul 2007 TIP - In this tip, contributor Mike Rothman examines these compliance paradigms and offers insights on how they can help organizations and auditors speak the same language.
Security survey finds increase in security standards adoption
SearchSecurity.com | 30 Oct 2008 ARTICLE - Ernst & Young's 2008 Global Information Security Survey finds both positive and negative trends in information security depending on how you look at the numbers.
RSA Conference 2006
SearchSecurity.com | 02.16.2006 CONFERENCE COVERAGE - Can't make it to RSA 2006? Check out our continuous coverage from the show floor.
Competing regulations clog road to compliance
SearchSecurity.com | 20 Oct 2005 ARTICLE - It's difficult for companies to cope with today's multitude of compliance regulations, but an expert at Information Security Decisions said security frameworks may be the answer.
Sustaining Sarbanes-Oxley Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs Published by: Tripwire, Inc. | 08 Jan 2009 WHITE PAPER - To successfully sustain compliance, organizations must implement best practices to ensure IT systems not only achieve a known and trusted state but they also maintain that state. Check out this white paper to learn how Tripwire solutions enable organizations to achieve and sustain SOX compliance.
ITIL Version 3 - What the Changes Could Mean to You Published by: Global Knowledge | 10 Dec 2008 WHITE PAPER - As the IT industry standardizes its operations to solve business problems in the most efficient, effective, economical, and equitable way, ITIL v3 becomes a useful and critical tool.
COBIT
18 Jul 2006 WORD - COBIT (Control Objectives for Information and Related Technology) is an international open standard that defines requirements for the control and security of sensitive data and provides a reference framework. COBIT, which ...
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.