<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.securityprocedure.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Security Management</title>
 <link>http://www.securityprocedure.com/tag/security-management</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>IT Risk Assessment Report and Template Toolkit</title>
 <link>http://www.securityprocedure.com/it-risk-assessment-report-and-template-toolkit</link>
 <description>&lt;p&gt;Download Free IT Risk Assessment Report and Template Toolkit&lt;br /&gt;
&lt;IMG SRC=&quot;/files/it-risk-assessment-report.png&quot; alt=&quot;IT Risk Assessment Report&quot;&gt;&lt;br /&gt;
This templates including Risk Register and IT Control for selected risk criteria such as:&lt;br /&gt;
&lt;b&gt;Risk Assessment Matrix:&lt;/b&gt;&lt;br /&gt;
- Vulnerability&lt;br /&gt;
- Threat&lt;br /&gt;
- Risk&lt;br /&gt;
- Risk Sumary&lt;br /&gt;
- Risk Likelihood&lt;br /&gt;
- Rating&lt;br /&gt;
- Risk&lt;br /&gt;
- Impact&lt;br /&gt;
- Rating&lt;br /&gt;
- Overall Risk Rating&lt;br /&gt;
- Analysis ofRelevant Controls and Other Factors&lt;br /&gt;
- Recommendations&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/it-risk-assessment-report-and-template-toolkit&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/it-risk-assessment-report-and-template-toolkit#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/risk-assessment">Risk Assessment</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/it-risk-assessment-report.png" length="20349" type="image/png" />
 <pubDate>Tue, 02 Mar 2010 13:17:18 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">301 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download Free IT Risk Assessment Templates	</title>
 <link>http://www.securityprocedure.com/download-free-it-risk-assessment-templates</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img12.imageshack.us/img12/9197/itriskassessmenttemplat.jpg&quot; alt=&quot;Download Free IT Risk Assessment Templates	&quot;&gt;&lt;br /&gt;
Download Free IT Risk Assessment Templates, this template is created using NIST-SP 800:30 standard for Risk Management Guide for Information Technology Systems. Covering some basic process during IT Risk Assessment that include: System Characterization, Threat Identification Vulnerability Identification, Control Analysis, Likelihood Determination,&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-free-it-risk-assessment-templates&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-free-it-risk-assessment-templates#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/nist-sp">NIST-SP</category>
 <category domain="http://www.securityprocedure.com/tag/risk-assessment">Risk Assessment</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <enclosure url="http://www.securityprocedure.com/files/it-risk-assessment-template.xls" length="16384" type="application/vnd.ms-excel" />
 <pubDate>Tue, 07 Apr 2009 14:11:56 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">298 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download IT General Control (ITGC) Audit Program Template</title>
 <link>http://www.securityprocedure.com/download-it-general-control-itgc-audit-program-template</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img502.imageshack.us/img502/2408/itgc.jpg&quot; alt=&quot;ITGC IT General Control&quot;&gt;&lt;br /&gt;
So basically what is the simplest approach for ITGC? do we should check every changes and modification in our application and infrastructure? or do we should only focus to significant one? The simplest approach is by using minimum requirement by the government/regulation. So here is some scope of ITGC based on Sarbanes Oxley Section 404&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Program Development Program Change&lt;/b&gt;&lt;br /&gt;
Acquire or develop application software	The organization&#039;s system development life cycle (SDLC) includes security, availability and processing integrity requirements of the organization.&lt;/p&gt;
&lt;p&gt;Acquire or develop application software	An adequate SDLC methodology has been established to serve as a basis for controlling development and maintenance activities, and the SDLC methodology is consistent with business and end-user strategies and objectives.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Logical Access&lt;/b&gt;&lt;br /&gt;
Ensure systems security	An information security policy exists and has been approved by an appropriate level of executive management.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-it-general-control-itgc-audit-program-template&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-it-general-control-itgc-audit-program-template#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/sarbanes-oxley">Sarbanes Oxley</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/ITGeneralControl.xls" length="29184" type="application/vnd.ms-excel" />
 <pubDate>Sat, 28 Feb 2009 01:11:27 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">296 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Data Retention Policy Free Download</title>
 <link>http://www.securityprocedure.com/data-retention-policy-free-download</link>
 <description>&lt;p&gt;The organization is subject to data retention requirements resulting from a mix of legal, industry, and business mandates. These data retention requirements govern the storage of the organization&#039;s information, records, and data. Regulations dictate that different data types be stored for specific periods. They also dictate the media storage format that must be used to store specific data types.&lt;/p&gt;
&lt;p&gt;The organization&#039;s Data Retention Policy exists to ensure all organization information, records, and data are retained and stored in compliance with legal, industry, and business regulations. It includes a policy you can customize to meet your needs as well as a risk assessment spreadsheet you can use to judge just how much your organization is at risk by not having this policy in place. &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://downloads.techrepublic.com.com/abstract.aspx?&amp;amp;kw=compliance&amp;amp;docid=239619&quot;&gt;Download Page&lt;/a&gt;&lt;/p&gt;
</description>
 <comments>http://www.securityprocedure.com/data-retention-policy-free-download#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <pubDate>Sat, 16 Aug 2008 23:36:20 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">267 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>OECD Guidelines for the Security of Information Systems and Networks: Towards a Culture of Security</title>
 <link>http://www.securityprocedure.com/oecd-guidelines-security-information-systems-and-networks-towards-culture-security</link>
 <description>&lt;p&gt;These guidelines apply to all participants in the new information society and suggest the need for a greater awareness and understanding of security issues, including the need to develop a &quot;culture of security&quot; - that is, a focus on security in the development of information systems and networks, and the adoption of new ways of thinking and behaving when using and interacting within information systems and networks. The guidelines constitute a foundation for work towards a culture of security throughout society.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/oecd-guidelines-security-information-systems-and-networks-towards-culture-security&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/oecd-guidelines-security-information-systems-and-networks-towards-culture-security#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <pubDate>Mon, 11 Aug 2008 00:26:05 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">258 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>What is Generally Accepted System Security Principles (GASSP/GSSP)?</title>
 <link>http://www.securityprocedure.com/what-generally-accepted-system-security-principles-gasspgssp</link>
 <description>&lt;p&gt;Generally Accepted System Security Principles incorporate the consensus, at a particular time, as to the principles, standards, conventions, and mechanisms that information security practitioners should employ, that information processing products should provide, and that information owners should acknowledge to ensure the security of information and information systems.&lt;/p&gt;
&lt;p&gt;GASSP relates to physical, technical, and administrative information security and encompasses pervasive, broad functional, and detailed security principles. GASSP nomenclature considers the terms policy, rules, procedures, and practices to relate to the organizational implementation of security. Information technology (IT) changes rapidly, and GASSP are expected to evolve accordingly. Consensus regarding accepted information security principles is achieved first within the GASSP Committee followed by international IT community review.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;GAAP versus GASSP?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/what-generally-accepted-system-security-principles-gasspgssp&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/what-generally-accepted-system-security-principles-gasspgssp#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <pubDate>Mon, 04 Aug 2008 19:39:13 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">253 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download Security Management And Risk Tracking 3.0.3, Free Security Management Application</title>
 <link>http://www.securityprocedure.com/download-security-management-and-risk-tracking-303-free-security-management-application</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img167.imageshack.us/img167/1160/securitymanagementandrirl6.png&quot;&gt;&lt;br /&gt;
If you are an Information System Auditor, an Security Analyst or even a Chief Information Officer. Then at some high level of management you will need this Free Security Management Application. Security Management And Risk Tracking is a web based application to manage information security practice. This is a comprehensive solution that enables a corporation to manage:&lt;br /&gt;
                                                                                                                                                                                                       · Information security policy&lt;br /&gt;
· Security policy exception handling&lt;br /&gt;
· Security Certification and Accreditation (SC&amp;amp;A)&lt;br /&gt;
· Issue tracking for security audit, pen testing, SOX, and so on&lt;br /&gt;
· Third party connection management&lt;br /&gt;
· Asset and vendor managementA number of other services are also included in this solution. This is an enterprise ready application that greatly reduces the time and effort to manage a security practice.&lt;/p&gt;
&lt;p&gt;Key Feature&lt;br /&gt;
· Web based user interface&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-security-management-and-risk-tracking-303-free-security-management-application&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-security-management-and-risk-tracking-303-free-security-management-application#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/download">Download</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <pubDate>Thu, 24 Jul 2008 23:42:36 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">247 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>OCS Inventory NG, Free Inventory Management tool for every auditor  </title>
 <link>http://www.securityprocedure.com/ocs-inventory-ng-free-inventory-management-tool-every-auditor</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img182.imageshack.us/img182/1649/ocsni1.png&quot; align=&quot;left&quot; hspace=&quot;5&quot;&gt;Perhaps, one of the biggest questions every internal IT auditor must answer is about IT Inventory Management. And the next question would be:&lt;/p&gt;
&lt;p&gt;- Do we know which software or hardware component is installed on a computer?&lt;br /&gt;
- Are we able to deploy software or configuration scripts on your computers?&lt;br /&gt;
- Do we know all devices connected to your IT network?&lt;/p&gt;
&lt;p&gt;This question is easy to be answered if we use proprietary solution from Microsoft SMS or Novell, however if we want to rely to Open Source then OCS Inventory NG is one of the best choice. OCS Inventory NG is an application designed to help a network or system administrator keep track of the computers configuration and software that are installed on the network.&lt;/p&gt;
&lt;p&gt;By using this application every question above could be answered within a short period of time. Why don&#039;t you try?&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.ocsinventory-ng.org/ &quot;&gt;Website&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/ocs-inventory-ng-free-inventory-management-tool-every-auditor&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/ocs-inventory-ng-free-inventory-management-tool-every-auditor#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/download">Download</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <pubDate>Fri, 18 Jul 2008 01:41:48 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">242 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>What is End Point Security?</title>
 <link>http://www.securityprocedure.com/what-end-point-security</link>
 <description>&lt;p&gt;Since the massive implementation of information technology, the need of proper end point security become one of the critical discussion in the company about how manage end point security effectively.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;End Point Security Definition:&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A strategy in which security software is distributed to end-user devices but centrally managed [&lt;a href=&quot;http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci1121273,00.html &quot;&gt;searchsecurity.techtarget.com&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;An information security concept that basically means that each device (end-point) is responsible for its own security [&lt;a href=&quot;http://en.wikipedia.org/wiki/End_point_security &quot;&gt;wikipedia.com&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;An individual computer system or device that acts as a network client and serves as a workstation or personal computing device[&lt;a href=&quot;http://www.endpointsecurity.org&quot;&gt;endpointsecurity.org&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Example of&amp;nbsp; End Point Devices:&lt;br /&gt;
&lt;/b&gt;Laptop, PCs, Handhelds, specialized equipment such as inventory scanners and point-of-sale terminals&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/what-end-point-security&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/what-end-point-security#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <pubDate>Sat, 12 Jul 2008 19:44:01 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">232 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Anatomy of an Auditing System</title>
 <link>http://www.securityprocedure.com/anatomy-auditing-system</link>
 <description>&lt;p&gt;An auditing system consists of three components: the logger, the analyzer, and the notifier. These components collect data, analyze it, and report the results.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;1. Logger&lt;/b&gt;&lt;br /&gt;
Logging mechanisms record information. The type and quantity of information are dictated by system or program configuration parameters. The mechanisms may record information in binary or human-readable form or transmit it directly to an analysis mechanism (see Section 21.2.2). A log-viewing tool is usually provided if the logs are recorded in binary form, so a user can examine the raw data or manipulate it using text-processing tools.&lt;/p&gt;
&lt;p&gt;EXAMPLE: Microsoft&#039;s Windows NT has three different sets of logs. The system event log contains records of events that Microsoft has determined warrant recording, such as system crashes, component failures, and other events. The application event log contains records that applications have added. These records are under the control of the applications. The security event log contains records corresponding to security-critical events such as logging in and out, system resource overuses, and accesses to system files. Only administrators can access the security event log.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/anatomy-auditing-system&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/anatomy-auditing-system#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/audit">Audit</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <pubDate>Fri, 04 Jul 2008 16:09:35 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">191 at http://www.securityprocedure.com</guid>
</item>
</channel>
</rss>

