![]() |
Security Manual TemplateISO27000, Sarbanes - Oxley, PCI-DSS & HIPAA CompliantMulti-Country License Options
|
The License for the Security Manual Template can be purchased for use for either by a single company in a single country, single company in a country group like the EU, or by a single company for worldwide use. License Options
License ConditionsThe template can be placed on the enterprise's Intranet and be used as the standard for all divisions and operating units of the enterprise. The template is not for re-sale or re-distribution by consultants or VARs. If a consultant or a VAR wishes to use this for its clients Janco Associates should be contacted directly Janco can provide coordination services for the enterprise on a time and materials basis. In addition Janco can save copies of a companies customized DRP in its archives for retrieval in by the enterprise. Contact us directly for pricing of these services at +011 435 940-9300 x 101. Testimonials
This template is not for resale or re-distribution
Security Policies and Procedures Multi-Site Implementation ConsiderationsCIOs and Lawyers Must Communicate
IT chiefs and lawyers must learn to speak the same language if they are
to work together to help organisations avoid risk. And although responsibility for IT risk management, the careful
balancing act of businesses benefit against liability,must not begin and end
with the IT department, it is important to run any policies past the
techies.
It is vital the IT crowd is consulted, agrees with and has ownership of any policies that directly affect them, and technical teams must make the effort to try and communicate with legal eagles in a language other than IT speak. It is better to have a legal team which will tell the IT department what we need to be doing. But lawyers being lawyers, it is very difficult to work with them to understand what we want and if they could talk to us in an IT language life would be much easier. If you express risk in the different languages make sure things are transparent and everyone does understand who is responsible for what. - more infoFactors to Consider in a Disaster Recovery & Business Continuity PlanThe Janco Disaster Recovery Plan & Business Continuity Template takes into consideration all of the items related to various layers of operations that most enterprises need to consider if they want to continue after a disaster occurs. These include:
Where CIOs spend their timeIn a survey of CIOs, it was found that they spend most of their time:
Some improvement in the job marketA technology job board is seeing a steady uptick in technology jobs for the financial industry. After the economys meltdown in 2008 and 2009, its taken some time to see recovery in this segment. If you have technology experience in the industry, there are jobs to be had. Programming skills are way up in terms of demand, especially the C languages with C# being the skill most sought after right now, along with skills in C and C++. In New York City and the metropolitan area, financial technology positions garner 20 percent higher salaries than the general technology population. There is good news on the technology jobs front if you have prior banking or financial industry experience. Salaries are higher than the average tech job, especially on Wall Street. - more infoNew Policy Templates Can be CustomizedDocumenting
a clear set of IT policies is a resource-intensive process for IT managers, due
to the research and writing time involved. And once policies are created, the
next step is to communicate and gain acceptance for those policies throughout
the organization. Wouldn't it be nice to start with boiler-plate templates that
require only minor customization?
Janco Associates
is offering you CIO IT Infrastructure Policy Bundle. This updated,
time-saving package will provide you with a stocked library of over 200 pages of
policy templates. Plus, you get the tools, techniques and advice you need to
successfully apply these policies in your
company. CIO continue to run with tight budgetsOverall server spending in enterprises remains weak in 2010 as companies continue to look for ways to save money following the economic downturn, according to research firm TheInfoPro. According to the survey, which gathered data from 252 decision makers at Fortune 1000 companies, 38 percent plan to reduce server budgets this year compared to 2009, while 25 percent plan to spend more. Though demand for server hardware has picked up, spending has flattened due to growing trends like virtualization, which helps manage a larger number of tasks on fewer servers. - more infoWhat is the Chief Technology Officer's (CTO) Role
You can get more by getting the Internet and Information Technology Position Descriptions Handiguide - 2010 version. - more infoVirtualization improves disaster planning and change control
The reasons often given are:
I.T. hiring picks upSalaries and hiring are both on the rise, Janco reports. The I.T. jobs outlook is strongest among large companies, where many chief information officers have received the go-ahead to fulfill I.T. positions that were left unfulfilled last year, Janco Associates Inc., a management consulting firm specializing in information systems technology, says in its Mid-Year 2010 IT Salary Survey report. In contrast, technology executives at smaller companies are being more cautious about hiring out of concern that the economic recovery will not be strong enough to support increased I.T. spending, the survey found. Nonetheless, most chief information officers who participated in the survey said in post-survey interviews that theyre planning for 2011 with the assumption that the economy will improve early next year. If that holds true, I.T. hiring and compensation should rise for more companies, Janco says - more infoConsequences of too much social networkingFacebook, MySpace, and other social networking sites make it easy to share information with friends. If you are not utilizing safety features and precautions, however, you are also sharing that information with strangers. Posting too much information on your profile can have consequences that reach all the way from your bank account to your future employment prospects. According to Consumer Reports, in the last year 9 percent of social network users experienced some form of abuse, such as malware infections, scams, identity theft, or harassment. Many of these incidents are preventable, if you educate yourself about what to do and what not to do on social networking sites. Similarly, an increasing number of prospective employers are turning to social networking sites to research applicants. Does your profile represent you the same way you would represent yourself in an interview? - more infoChallenges CIOs faceCIOs are now challenged more than any time in the past with the economic earthquake around the globe CIOs have to be smarter, creative and innovative. The only way for CIOs to survive the world economic reset in a knowledge age is to capitalize on our human capital, put their staffs creativity to work, stoke our innovative furnace. There are many ways to fuel the creative fires - from management techniques, to team building, and effectively leveraging existing and emerging technological investments. However, the key is infrastructure. CIOs that have a one that address metrics, change management, version control, system development methodology, service management, and human resources have a better chance to make it through these tough times. Preventing Data Breaches
This Security Manual for the Internet and Information Technology is over 220 pages in length. All versions of the Security Manual template include both the Business & IT Impact Questionnaire and the Threat & Vulnerability Assessment Tool (both were redesigned to address Sarbanes Oxley compliance). In addition, the Security Manual Template PREMIUM Edition contains 16 detail job descriptions that apply specifically to security and Sarbanes Oxley, ISO 27000, PCI DSS, and HIPAA. - more infoReasons why CIOs and CTOs get FiredTop ten list of things that fired CIOs do 1. Do not have a disaster recovery and business continuity plan integrated with a backup/archiving program. 2. Ignore warning signs 3. Do not document changes 4. Do not use logging processes 5. Do not install updates 6. Save money by not purchasing upgrades 7. Do not manage passwords well 8. Never say no to anyone 9. Never say yes to anyone 10. Do not train a replacement - more infoProject Managers are paid wellCompanies seem willing to provide solid compensation for project maagers. According to a CIO.com article reporting results of the Project Management Institute's (PMI) 2009 Project Management Salary Survey, the median base salary for a project management professional in the United States is $100,000. Three-quarters of survey respondents take home more than $84,000 a year. Even during the recession, between fall 2008 and fall 2009, 53 percent of American project managers got a raise. Thirty-four percent had salaries frozen, and 14 percent experienced a pay cut. And project management pros have an optimistic outlook for 2010. Sixty-seven percent of respondents believe their salaries will grow this year, while just 4 percent think their salaries will drop. You have several options to obtain this study. You can get a summary for free if you participate by providing more than ten (10) data points or you have several option on how to purchase the data. Summary Results and Changes in Demand for IT Jobs 2010
The Janco Associates, Inc. salary survey draws on data collected throughout the year by extensive internet-based and completed survey forms sent to businesses throughout the United States and Canada. Over 300 companies participate in the survey - more infoCIO and IT departments are blamed for user shortfallsNow the CIO not only must be politically correct, but he must also be clairvoyant and understand what can go wrong, be misused, or be abused. The IT Infrastructure must be robust to address this. When systems are abused the easiest scapegoat is the IT Department. In
the recent school webcam case at the Pennsylvania school district the IT
department was blamed because they not only failed to inform school officials
and administrators of the tracking capabilities of the software, but argued that
telling students about the software's ability to remotely trigger notebook
Webcams would "defeat its purpose" as a way to recover lost or stolen
computers. Over one third of HR executives ignore unemployment status of employment candidates
The survey also revealed that when making hiring decisions, 44 percent of executives have no preference for a candidate's employment status. In addition, one-third of New England hiring managers and human resources professionals are considering rehiring information technology (IT) employees whom they had laid off.
Although in the minority, 19 percent of those surveyed do prefer candidates who are currently employed as regular, full-time employees. Candidates who are either employed full-time or currently employed as temporary or contract workers are preferred by 22 percent. Of all hiring executives, 53 percent did not care if a candidate was laid off in a first round as opposed to a subsequent round. While the majority did not have an issue with laid off workers, 17 percent of respondents found it more acceptable if a worker was not one of the first to be laid off. - more infoUS at risk for cyber attacks according to studyA survey released by Lumension Security Inc. states that nearly three-quarters of federal IT decision-makers who work in national defense and security departments or agencies say the possibility is high for a cyber attack by a foreign nation in the next year. Additionally, a third of these respondents say they have already experienced such a cyber attack within the last year. Of about 200 IT security managers in civilian and noncivilian federal agencies surveyed, 61% said there was a "high" threat of an attack being launched by a foreign nation sometime in the next year.
At the same time, more than four out of 10 respondents in the Lumension survey said that they believe the U.S. government's ability to defend against the attacks is "poor" to "fair" at best. - more infoFeds could learn from private sector ITThe federal government can learn a lot from the private sector to improve IT program management and customer service and create a more modern government, concluded attendees of a forum comprised of both federal and private-sector leaders.The government should take a more business-minded approach to how it manages its IT projects, as well as step up efforts already in place to increase transparency and accountability, according to a recently released report about the White House Forum on Modernizing Government. - more infoPCI DSS compliance is more than checklist managmentPCI DSS applies to any organization that accepts, stores or processes payment cards of any type and is a comprehensive checklist of actions these organizations must take to improve the security of global payment systems. Although the adoption of PCI DSS by an organization will most likely improve its security posture, being compliant with the PCI DSS does not ensure the organization is secure. If Enterprises mechanically follow the PCI DSS checklist and our
organization suffers a data securitybreach, they are still held responsible, and
the organization still gets fined, suffers brand damage and may lose its ability
to process credit card transactions. While checklists are useful tools,
following them can lull us into a false sense of security. Cost cutting starts with simplifying operationsComplexity produces cost, so IT departments may choose to standardize on a handful of preferred technologies or vendors. The biggest line item in IT budgets is people, so staffing must be addressed. That could mean hiring freezes, cutting back on use of consultants, replacing employees who leave with automation technologies (not another person) and similar measures to limit spending on people. CIOs should plan proactively for spending cuts before they are mandated. That may involve rebalancing IT initiatives to focus on projects with near-term benefits while keeping momentum on longer-term, strategic projects. They also may need to align IT more closely with the business priorities, which are likely to focus on revenue. - more info
|





















Boston
- Results from new research released by Veritude, astaffing services provider,
indicate a positive sign for the New England economy. All surveyed executives in
New England, and across the country, are accepting of the economy as a reason
for an extended unemployment when reviewing candidates. Specifically, when it
came to examining the acceptable length of time for a candidate to be
unemployed, 36 percent of responding executives said they did not believe it
mattered how long a candidate was unemployed given the recessionary conditions,
with 36 percent indicating that six months or less was their ideal length of
unemployment. 