If you are in the security function of a medium sized organisation and you don't have the following under control..... well here's the list and a place to start if you don't:
- job descriptions for members of information security function
- list of business units and a key contact in each you know
- list of critical business processes and key applications for each business unit
- schedule for risk assessments of processes and applications
- some completed risk assessments (incorporating security policy compliance checks)
- security policy framework (aka ISMS)
- endorsed security policy
- some endorsed standards (esp. acceptable use, password, secure configuration )
- some processes
- some procedures (esp. Firewall mangement )
- matrix of security controls and results with forward schedule
- schedule for pen testing program for critical applications
- copies of business unit risk registers
- vulnerability management solution and some completed scans
- log management solution and plan for enabling logging on end devices and associated alerts
- security awareness material for induction training
- enterprise security strategy with list of treatments that security function are running with
- governance reports to stakeholders
About Me
- Matthew Hackling
- Matt runs his own security consultancy called Ronin Security. His focus is information security management and he has a keen interest in infrastructure and web application security. He's a CISSP and the current Branch Executive of the Melbourne chapter of the Australian Information Security Association.
Blog Archive
Labels
- AISA (1)
- australian information security market (1)
- career advice (1)
- causes (1)
- DoS (1)
- economics (1)
- FUD (1)
- futurism (1)
- information security governance (4)
- IPS (1)
- privacy (2)
- sacred cows (1)
- security patching (1)
- vulnerability management (1)
- webappsec (1)
Tuesday, August 24, 2010
Subscribe to:
Post Comments (Atom)
Handy Links
Matt's list of blogs
-
-
-
TEDxMaui -- Hack Yourself First3 weeks ago
-
-
-
FedRAMP: It’s Here but Not Yet Here2 months ago
-
Bunraku V0.0.36 months ago
-
GoGrid Security Breach10 months ago
0 comments:
Post a Comment