|
Colapse all |
Post message
ISO 27001 LA 2006-07-21 kartik netsec gmail com (1 replies) Hi guys, This is my 1st post at security focus. Well, I would like to have your valuable sugessions on ISO 27001 (LA). I have got 3 years working experiance (2yrs in Network Security) with MCSA,CCNA,CCNP,CCSA and CEH certifications. I would like to go for ISO 27001 program (Lead Auditor). Is i [ more ] [ reply ] Re: RE: Metrics in ISO 27001 2006-07-19 harshal mehta niiconsulting com (1 replies) Hi The requirement to measure the performance of IT security processes is a mandatory requirement by ISO 27001:2005. Measuring Security provides an approach to help management decide where to invest in additional security protection resources or identify and evaluate nonproductive controls. It [ more ] [ reply ] Re: Log Analysis 2006-07-19 harshal mehta niiconsulting com HI Logs are to be maintained and reviewed on a regular basis. As per ISO 27001 there is a control objective controls Audit logging Monitoring system use Protection of log information Administrator and operator logs So this means log has to be generated , it has to be reviewed , protec [ more ] [ reply ] Re: Fw: physical security 2006-07-19 harshal mehta niiconsulting com HI Physical security plays a pivotal role in implementation of ISO 27001. All physical controls applicable needs to be checked i can list some Access list Visitor Entry logs Server Room Security Server Room logs Environmental Ctrls Cabling UPS testing logs Movement of equipments Evacuat [ more ] [ reply ] RE: Log Analysis 2006-07-19 mohamed siddiqu wipro com Hi, Section A10.10 covers in detail on monitoring and logging. Siddiqu.T. -----Original Message----- From: Samir Pawaskar [mailto:samirp (at) eim (dot) ae [email concealed]] Sent: Wednesday, July 19, 2006 8:56 AM To: iso 27000; bs7799 (at) securityfocus (dot) com [email concealed] Subject: Re: Log Analysis The only control that I can think of is rel [ more ] [ reply ] Fw: physical security 2006-07-19 Samir Pawaskar (samirp eim ae) ----- Original Message ----- From: "Samir Pawaskar" <samirp (at) eim (dot) ae [email concealed]> To: "shakti velu" <shaktivelu88 (at) gmail (dot) com [email concealed]> Sent: Wednesday, July 19, 2006 7:18 AM Subject: Re: physical security > COntrols have to be there.. What depends entirely on the value of > information that you are securing and the le [ more ] [ reply ] Log Analysis 2006-07-18 iso 27000 (is27001 gmail com) (2 replies) Hi, I am new to ISO 27001 We are setting up a facility for log collection and analysis for all servers in datacenter. Right now we are looking at Unix syslog as central server and everyone pushing OS logs here. In future we are planning to go for ISO 27001 for our datacenter. Could someone throw [ more ] [ reply ] RE: Perimeter security 2006-07-18 Cadle Tom (TCadle EssilorUSA com) (1 replies) simply put it is the first line of defense in protecting your assets from malicious people/activity \tmc -----Original Message----- From: Vikrant [mailto:vikrant (at) albahja (dot) com [email concealed]] Sent: Tuesday, July 18, 2006 9:40 AM To: bs7799 (at) securityfocus (dot) com [email concealed] Subject: Perimeter security Hi all, How would you def [ more ] [ reply ] RE: Perimeter security 2006-07-18 Richard Feist (richard bluesec net) (1 replies) RE: Metrics in ISO 27001 2006-07-18 Clement, Ronald S. \(The Greentreee Group\) CTR (Ronald Clement deca mil) (1 replies) A good source of info would be: May 4, 2006: Draft Special Publication 800-80, Guide for Developing Performance Metrics for Information Security NIST's Computer Security Division has completed the initial public draft of Special Publication 800-80, Guide for Developing Performance Metrics for I [ more ] [ reply ] Metrics in ISO 27001 2006-07-18 stanley perreira (1979stanley gmail com) (3 replies) Hello, I am trying to develop metrics for the ISO 27001. There doesnot seem to be much of consensus on how to go about it ? What are we supposed to measure here - is it the effectiveness of the controls or how many controls are being followed ? [ more ] [ reply ] physical security 2006-07-18 shakti velu (shaktivelu88 gmail com) (4 replies) |
|
Privacy Statement |
Shakti Velu,
End user awareness is the key ... Keep them informed the latest phishing
threats...
Thanks
Siddiqu.T
-----Original Message-----
From: shakti velu [mailto:shaktivelu88 (at) gmail (dot) com [email concealed]]
Sent: Thursday, July 27, 2006 10:23 AM
To: bs7799 (at) securityfocus (dot) com [email concealed]
Subject: phishing threat
We have im
[ more ] [ reply ]