Disaster
Recovery & Business Continuity Template, Security Template, Disaster
Recovery & Business Continuity Audit Program, and Security Audit Program
Bundle
This bundle is fully compliant with Sarbanes-Oxley, HIPAA, PCI-DSS
and the ISO 27000 Series (ISO 27001 and ISO 27002). It has been updated to reflect all of the recent
legislation and other mandated requirements.
The
Security Manual Template has just been updated to
address issues such as SmartPhone and other PDAs
The
Security Audit Program contains over 400 unique
tasks divided into 11 areas of audit focus which are then divided into
38 separate task groupings. The audit program is one that either an
external or an internal auditor can use to validate the compliance of
the Information Technology and the enterprise to ISO 27000 (Formerly ISO 17799),Sarbanes-Oxley, HIPAA, and PCI-DSS.
The
Disaster Recovery / Business
Continuity Audit program identifies control objectives that are
meet by the audit program. There are 36 specific items that the
audit covers in the 11 page audit program.
The ISO 27000 series is a set of individual standards and documents
defined as follows:
·ISO 27001 - The specification for an
Information Security Management System (ISMS) replaced the BS7799-2
standard.
·ISO 27002 – The ISO 27002 standard is a
renaming of the ISO 17799 standard, which is a code of practice for
information security. It outlines controls and control mechanisms,
which may be implemented subject to the guidance provided within ISO
27001.
·ISO 27003 – This is a PROPOSED Standard,
which has yet to be completely defined. This will be the official
number of a new standard intended to offer guidance for the
implementation of an ISMS (Information Security Management System). The
purpose of this proposed development is to provide help and guidance in
implementing ISMS. This will be a quality control standard when it is
released. ISO 27003 will focus on utilizing the Plan-Do-Act-Check (PDCA)
method, when establishing, implementing, reviewing, and improving the
ISMS.
·ISO 27004 - This is the designated number
for a PROPOSED standard covering information security, system
management, measurement, and metrics.
·ISO 27005 – This is the name of a PROPOSED
standard emerging standard covering information security risk
management. As with the other standards within the ISO 27000 series, no
firm dates have been established for its release. However, it will
define the ISMS risk management process, including identification of
assets, threats and vulnerabilities. This is the ISO number assigned
for an emerging standard for information security risk management.
·ISO 27006 - This standard offers guidelines
for the accreditation of organizations that offer certification and
registration with respect to ISMS.
Disaster Planning/Business Continuity and Security Auditing News
05/12/2008 - Security Manager's Journal: Getting the best from an audit Security Manager's Journal: Getting the best from an audit * Multiple short outages can add up to major data center problems * Windows Vista more secure than XP, says security company * Civic groups urge DOJ probe of possible ...-
more information
05/12/2008 - Availabe Consultants Excellent IT Audit/Sox/Information Security... ... Risk Assessment & Management, Designing of Security Policies & Procedures, ITIL/ITSM audit/implementation, developing Business Continuity Plans (BCP), Disaster Recovery procedures (DRP) and ISO17799/ISO 27001 Consulting. ...-
more information
05/08/2008 - Opening for Manager-Information Security - Bangalore - MNC Bank
BCP/DRP: · Ensure ISMs test/coordinate the disaster recovery activity in an event of a disaster. · Review the Business Continuity Process inline with Resource Management support · Track & Publish Change Management process across BUs ...-
more information
05/08/2008 - {c2c-jobs-usa} URGENT REQUIREMENT FOR UNIX ADMIN LOCAL PREFERRED
Scripting experience, H/W (p series, x series), partitioning & virtualization, software and hardware upgrade and AIX security. · Experience with Sarbanes-Oxely and audit compliance, disaster recovery, remote access configuration and ...-
more information
05/06/2008 - Product Manager, Head of Managed IT Services - Church ...
Product Manager, Head of Managed IT Services... managed IT office, Disaster Recovery, BCP etc). The Product Manager, Head of Managed IT Services must have... (From CityJobs.com)-
more information