JancoJanco Forum

News Feed

Feed
Description

Janco Mobile Pages

Join Now

Home
Search
Templates
Salary Survey
HandiGuides
Job Descriptions
Individual Policies
Compliance Tools
White Papers
Update Service
Bundles & Special Offers
Software
Promotions

DRP, BCP, and Security Template and Audit BundleDisaster Recovery & Business Continuity Template, Security Template, Disaster Recovery & Business Continuity Audit Program, and Security Audit Program Bundle

This bundle is fully compliant with Sarbanes-Oxley, HIPAA, PCI-DSS and the ISO 27000 Series (ISO 27001 and ISO 27002).  It has been updated to reflect all of the recent legislation and other mandated requirements.

The Disaster Planning and Business Continuity Template has been selected by over 2,000 enterprise as the foundation of their DRP and BCP programs.

The Security Manual Template has just been updated to address issues such as SmartPhone and other PDAs

The Security Audit Program contains over 400 unique tasks divided into 11 areas of audit focus which are then divided into 38 separate task groupings. The audit program is one that either an external or an internal auditor can use to validate the compliance of the Information Technology and the enterprise to ISO 27000 (Formerly ISO 17799),Sarbanes-Oxley, HIPAA, and PCI-DSS.

The Disaster Recovery / Business Continuity Audit program identifies control objectives that are meet by the audit program.  There are 36 specific items that the audit covers in the 11 page audit program. 

Order Now

 

 

The ISO 27000 series is a set of individual standards and documents defined as follows:

·         ISO 27001 - The specification for an Information Security Management System (ISMS) replaced the BS7799-2 standard. 
                                                         Order Now

·         ISO 27002 – The ISO 27002 standard is a renaming of the ISO 17799 standard, which is a code of practice for information security.  It outlines controls and control mechanisms, which may be implemented subject to the guidance provided within ISO 27001. 
 

                                                                Order Now

·         ISO 27003 – This is a PROPOSED Standard, which has yet to be completely defined.  This will be the official number of a new standard intended to offer guidance for the implementation of an ISMS (Information Security Management System).  The purpose of this proposed development is to provide help and guidance in implementing ISMS.  This will be a quality control standard when it is released.  ISO 27003 will focus on utilizing the Plan-Do-Act-Check (PDCA) method, when establishing, implementing, reviewing, and improving the ISMS.

                               

·         ISO 27004 - This is the designated number for a PROPOSED standard covering information security, system management, measurement, and metrics.

·         ISO 27005 – This is the name of a PROPOSED standard emerging standard covering information security risk management.  As with the other standards within the ISO 27000 series, no firm dates have been established for its release.  However, it will define the ISMS risk management process, including identification of assets, threats and vulnerabilities.  This is the ISO number assigned for an emerging standard for information security risk management.

·         ISO 27006 - This standard offers guidelines for the accreditation of organizations that offer certification and registration with respect to ISMS.

 

 

                                                         Order Now

 

 

 

 

 

Disaster Planning/Business Continuity  and Security Auditing News

05/17/2008 - McGraw Hill IT Auditing
CISSP-ISSMP, CISA, Audit Team Lead, Cisco Systems, Inc. Plan for and manage an effective IT audit program using the in-depth information contained in this comprehensive resource. Written by experienced IT audit and security ...- more information

 

05/16/2008 - CNC Administrator
... Monitor and maintain application back-up and disaster recovery procedures • Maintain and audit application level security • Review and install application patches, ESUs, ASUs, and upgrades • Configure and maintain ...- more information

 

05/14/2008 - In this issue Furniture Salesman Pleads Guilty To Spying For China ...
Twelve percent of the DEA’s intelligence analysts last year did not have the security clearances necessary or were otherwise unauthorized to do their jobs, a new Justice Department audit concludes. The audit says the Drug Enforcement ...- more information

 

05/13/2008 - REQ : UNIX ADMIN
Scripting experience, H/W (p series, x series), partitioning & virtualization, software and hardware upgrade and AIX security. Experience with Sarbanes-Oxely and audit compliance, disaster recovery, remote access configuration and ...- more information

 

05/12/2008 - Security Manager's Journal: Getting the best from an audit
Security Manager's Journal: Getting the best from an audit * Multiple short outages can add up to major data center problems * Windows Vista more secure than XP, says security company * Civic groups urge DOJ probe of possible ...- more information

 

 

News HTML
SAFE Shopping

© 2008 Janco Associates, Inc. - ALL RIGHTS RESERVED -- Revised: 05/02/08