Archive for August, 2007

How to Begin a Policy Program

Wednesday, August 15th, 2007

Author: Thomas Peltier, President, Thomas R. Peltier Associates, LLC

All organizations need to have an established set of policies and standards to govern their operating environment. There has been an established process to bring new and updated policies and standards into the organization. The key to a successful implementation of new policy is understanding how this process works and how to use this knowledge for a successful implementation of the task at hand. (more…)

Reducing Risk through Public-Private Partnership: The National Infrastructure Protection Plan (NIPP) – Information Technology (IT) Sector Plan

Wednesday, August 15th, 2007

Author: Dan Lohrmann, CISO, State of Michigan

In mid-July, our nation watched as the U.S. Homeland Security Secretary Michael Chertoff went on national television and described the increased threat level to our country. “I believe we are entering a period this summer of increased risk,” Chertoff told the Chicago Tribune’s editorial board in an unusually blunt and frank assessment of America’s terror threat level. “We could easily be attacked,” Chertoff added. “The intent to attack us remains as strong as it was on Sept. 10, 2001.” (more…)

The CISO Mantra: Protect the Data!

Wednesday, August 15th, 2007

Author: Ernie Hayden, CISSP CEH, CISO Port of Seattle

As we all know, in order to be successful at any task, you need to be focused on the outcome of your actions. As an individual assigned responsibility for information security at the Port of Seattle, I’ve found that a primary focus – or “mantra” – is to “Protect the Data.” In other words, besides worrying about the CIA (Confidentiality, Integrity and Availability) issues each day, the key point is to maintain focus on protecting the confidentiality, integrity and availability of the data. (more…)

Data Breaches, Decision-Making, and Risk: a Primer

Wednesday, August 15th, 2007

>Author: Miki Calero, CISM, PMP, Information Security Senior, American Electric Power

They were made after ChoicePoint; they will follow the latest organization named in the Chronology of Data Breaches: decisions. Were decisions regarding data breaches the product of a rational process? Did these decisions mitigate risk as intended, or inadvertently ignore it? We can gain insight into these questions outside the security field. (more…)

SecureWorld Expo Announces Seagate as Platinum Sponsor

Wednesday, August 15th, 2007

SecureWorld Expo has solidified a key platinum sponsorship with Seagate Technology (NYSE:STX), the worldwide leader in storage products for a wide-range of applications, including Enterprise, Desktop, Mobile Computing, Consumer Electronics and Branded Solutions. This partnership provides the security community a connection to the latest in digital data storage. Seagate will demonstrate the strongest protection available in storage security technologies for government officials and corporate security professionals throughout the nation. (more…)