Monday | 6 July, 2009
CSO

Stories about: ISO

  • +

    How to Write an Information Security Policy 17/06/2009 05:31:00

    An Information Security Policy is the cornerstone of an Information Security Program. It should reflect the organization's objectives for security and the agreed upon management strategy for securing information.
  • +

    China to propose WLAN security standard for global use again 16/06/2009 20:38:00

    China will submit its wireless LAN security protocol to the International Organization for Standardization (ISO) for consideration as a global standard, years after its rejection by the standards body incensed Chinese backers.
  • +

    Evolution of the CSO 11/06/2009 07:20:00

    It's been almost 15 years since David Kent first came to Genzyme, a biotech firm headquartered in Cambridge, Mass., that develops medical treatments for ailments such as certain genetic diseases and some forms of cancer. In 1994, the company had less than $200 million in sales, and only about 1,000 employees-a stark contrast to its worldwide workforce of 11,000 today and the $4.6 billion in revenue it reported in 2008.
  • +

    Security analyst to DLP vendors: watch your language 04/06/2009 04:36:00

    Data Loss Prevention (DLP) is all the rage in this era of data security breaches and increasingly clever malware attacks. Naturally, every vendor in the security market wants a piece of the action.
  • +

    Cloud Security: Danger (and Opportunity) Ahead 20/05/2009 00:05:00

    The dramatic change in the rate of adoption and the amount of discussion taking place regarding cloud computing demands that this technology, or rather a set of related technologies, continue to evolve utilizing a security-sensitive design.
  • +

    Information systems audit: the basics 18/05/2009 23:57:00

    In the early days of computers, many people were suspicious of their ability to replace human beings performing complex tasks. The first business software applications were mostly in the domain of finance and accounting. The numbers from paper statements and receipts were entered into the computer, which would perform calculations and create reports. Computers were audited using sampling techniques. An auditor would collect the original paper statements and receipts, manually perform the calculations used to create each report, and compare the results of the manual calculation with those generated by the computer. In the early days, accountants would often find programming errors, and these were computer audit findings.
  • +

    How SCAP Brought Sanity to Vulnerability Management 12/05/2009 00:10:00

    Orbitz CISO Ed Bellis explains how the proliferation of vulnerability assessment products and services has created chaos, and how SCAP may be the answer.
  • +

    Swine Flu Prompts Aussie CIOs to Revisit Business Continuity Plans 28/04/2009 10:28:00

    Australian health authorities may have given the all clear for two local suspected cases of the [[artnid:300804|swine flu virus|new]] -- which has killed more than 80 people in Mexico and infected 20 in the United States -- but concern over the spread of the potentially fatal disease has local CIOs revisiting their business continuity plans (BCP).
  • +

    Cloud security stokes concerns at RSA 24/04/2009 09:19:00

    Two words -- cloud security -- dominated discussion and drove the action this week at RSA Conference 2009.
  • +

    Security's Role in Handling Layoffs 09/04/2009 01:41:00

    Layoffs are an unfortunate reality in this economic climate. Security has a critical role in helping support both the departing employees and the organization
  • +

    3 Ways Pen Testing Helps DLP (and 2 Ways It Doesn't) 02/04/2009 09:15:00

    Orbitz CISO Ed Bellis says penetration testing is a valuable tool in his data loss prevention arsenal. But it won't help him find everything.
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
ARN Polls

Is your company prepared for a cyber attack?

Yes
No
View Results
 
Whitepaper

Reducing the risk of insider abuse

The potential for insider abuse can never be eliminated completely, but the steps outlined in this white paper can reduce the potential for such abuse. Read on to ensure no one person can alter your operations to their personal advantage or to the detriment of your organisation.

Sponsored Links