<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.securityprocedure.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Documents</title>
 <link>http://www.securityprocedure.com/tag/documents</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>IT Service Management (ITSM) Strategy Templates</title>
 <link>http://www.securityprocedure.com/it-service-management-itsm-strategy-templates</link>
 <description>&lt;p&gt;Download Free ITIL/ITSM IT Service Management Strategy Templates&lt;br /&gt;
&lt;IMG SRC=&quot;/files/it-service-management-strategy-templates.png&quot; alt=&quot;Download Free IT Service Management Strategy Templates&quot;&gt;&lt;/p&gt;
&lt;p&gt;1	&lt;COMPANY&gt; Service Management Framework&lt;/p&gt;
&lt;p&gt;1.1	Background&lt;br /&gt;
The &lt;COMPANY&gt; IT community continually seeks to develop best practice IT management processes to improve IT services.  Since 20XX &lt;COMPANY&gt; IT has incorporated processes developed from the ITIL framework.  In 2007 this work guided the introduction of the Service Management Framework v1.0.  In 20XX progress will be made into incorporating ITIL version 3, the Service Lifecycle Approach, while supporting work to date on improving processes for Problem, Incident and Change Management and to further distinguish the Roles and Responsibilities of supporting teams. &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/it-service-management-itsm-strategy-templates&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/it-service-management-itsm-strategy-templates#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/download">Download</category>
 <category domain="http://www.securityprocedure.com/tag/itil">ITIL</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/it-service-management-strategy-templates.doc" length="38400" type="application/msword" />
 <pubDate>Sun, 13 Jun 2010 15:40:51 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">302 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>IT Risk Assessment Report and Template Toolkit</title>
 <link>http://www.securityprocedure.com/it-risk-assessment-report-and-template-toolkit</link>
 <description>&lt;p&gt;Download Free IT Risk Assessment Report and Template Toolkit&lt;br /&gt;
&lt;IMG SRC=&quot;/files/it-risk-assessment-report.png&quot; alt=&quot;IT Risk Assessment Report&quot;&gt;&lt;br /&gt;
This templates including Risk Register and IT Control for selected risk criteria such as:&lt;br /&gt;
&lt;b&gt;Risk Assessment Matrix:&lt;/b&gt;&lt;br /&gt;
- Vulnerability&lt;br /&gt;
- Threat&lt;br /&gt;
- Risk&lt;br /&gt;
- Risk Sumary&lt;br /&gt;
- Risk Likelihood&lt;br /&gt;
- Rating&lt;br /&gt;
- Risk&lt;br /&gt;
- Impact&lt;br /&gt;
- Rating&lt;br /&gt;
- Overall Risk Rating&lt;br /&gt;
- Analysis ofRelevant Controls and Other Factors&lt;br /&gt;
- Recommendations&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/it-risk-assessment-report-and-template-toolkit&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/it-risk-assessment-report-and-template-toolkit#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/risk-assessment">Risk Assessment</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/it-risk-assessment-report.png" length="20349" type="image/png" />
 <pubDate>Tue, 02 Mar 2010 13:17:18 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">301 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download Free IT Risk Assessment Templates	</title>
 <link>http://www.securityprocedure.com/download-free-it-risk-assessment-templates</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img12.imageshack.us/img12/9197/itriskassessmenttemplat.jpg&quot; alt=&quot;Download Free IT Risk Assessment Templates	&quot;&gt;&lt;br /&gt;
Download Free IT Risk Assessment Templates, this template is created using NIST-SP 800:30 standard for Risk Management Guide for Information Technology Systems. Covering some basic process during IT Risk Assessment that include: System Characterization, Threat Identification Vulnerability Identification, Control Analysis, Likelihood Determination,&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-free-it-risk-assessment-templates&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-free-it-risk-assessment-templates#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/nist-sp">NIST-SP</category>
 <category domain="http://www.securityprocedure.com/tag/risk-assessment">Risk Assessment</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <enclosure url="http://www.securityprocedure.com/files/it-risk-assessment-template.xls" length="16384" type="application/vnd.ms-excel" />
 <pubDate>Tue, 07 Apr 2009 14:11:56 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">298 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>NIST IT Risk Management Guidelines</title>
 <link>http://www.securityprocedure.com/nist-it-risk-management-guidelines</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://i39.tinypic.com/ei13dv.jpg&quot; alt=&quot;IT Risk Management Guidelines&quot;&gt;&lt;/p&gt;
&lt;p&gt;This NIST Guidelines covers:&lt;br /&gt;
1. IT Risk Management&lt;br /&gt;
2. IT Risk Assessment&lt;br /&gt;
3. IT Risk Mitigations&lt;/p&gt;
&lt;p&gt;Every organization has a mission. In this digital era, as organizations use automated information technology (IT) systems1 to process their information for better support of their missions, risk management plays a critical role in protecting an organization’s information assets, and therefore its mission, from IT-related risk.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/nist-it-risk-management-guidelines&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/nist-it-risk-management-guidelines#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/risk-assessment">Risk Assessment</category>
 <pubDate>Wed, 01 Apr 2009 14:20:06 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">297 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download IT General Control (ITGC) Audit Program Template</title>
 <link>http://www.securityprocedure.com/download-it-general-control-itgc-audit-program-template</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img502.imageshack.us/img502/2408/itgc.jpg&quot; alt=&quot;ITGC IT General Control&quot;&gt;&lt;br /&gt;
So basically what is the simplest approach for ITGC? do we should check every changes and modification in our application and infrastructure? or do we should only focus to significant one? The simplest approach is by using minimum requirement by the government/regulation. So here is some scope of ITGC based on Sarbanes Oxley Section 404&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Program Development Program Change&lt;/b&gt;&lt;br /&gt;
Acquire or develop application software	The organization&#039;s system development life cycle (SDLC) includes security, availability and processing integrity requirements of the organization.&lt;/p&gt;
&lt;p&gt;Acquire or develop application software	An adequate SDLC methodology has been established to serve as a basis for controlling development and maintenance activities, and the SDLC methodology is consistent with business and end-user strategies and objectives.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Logical Access&lt;/b&gt;&lt;br /&gt;
Ensure systems security	An information security policy exists and has been approved by an appropriate level of executive management.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-it-general-control-itgc-audit-program-template&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-it-general-control-itgc-audit-program-template#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/sarbanes-oxley">Sarbanes Oxley</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/ITGeneralControl.xls" length="29184" type="application/vnd.ms-excel" />
 <pubDate>Sat, 28 Feb 2009 01:11:27 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">296 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download Network Security Service Level Agreement (SLA) Sample Templates</title>
 <link>http://www.securityprocedure.com/download-network-security-service-level-agreement-sla-sample-templates</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img5.imageshack.us/img5/7025/slaan1.jpg&quot;&gt;&lt;br /&gt;
Below sample service level agreement (SLA) for supporting security event feeds from network devices. This sample SLA is arranged between the network support team (NetEng) and the team to whom security monitoring is assigned (InfoSec).&lt;/p&gt;
&lt;p&gt;The purpose of this document is to clarify support responsibilities and expectations. Specifically, it outlines:&lt;br /&gt;
- Services provided by NetEng to support network security event recording for monitoring and incident response&lt;/p&gt;
&lt;p&gt;- General levels of response, availability, and maintenance associated with these services&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-network-security-service-level-agreement-sla-sample-templates&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-network-security-service-level-agreement-sla-sample-templates#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/download">Download</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/service-level-agreement-information-security-and-network-engineering.doc" length="49664" type="application/msword" />
 <pubDate>Sat, 14 Feb 2009 18:32:53 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">294 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>How good is your IT Security Administration</title>
 <link>http://www.securityprocedure.com/how-good-your-it-security-administration</link>
 <description>&lt;p&gt;So how good is your IT Security Administration? Below some of the list that is intended as a guide to the various areas that need to be reviewed to conduct a complete assessment of security administration.&lt;/p&gt;
&lt;p&gt;• Organization and policies&lt;br /&gt;
• Procedures and post orders&lt;br /&gt;
• Personnel selection&lt;br /&gt;
• Staffing and background checks&lt;br /&gt;
• Education and awareness&lt;br /&gt;
• Contract management&lt;/p&gt;
&lt;p&gt;Each aspect of this assessment is equally important to providing the client with a complete picture of the operation. You should understand that the assessment process is intended to document the current status of the security program for the client&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/how-good-your-it-security-administration&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/how-good-your-it-security-administration#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/computer-security">Computer Security</category>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/forensics">Forensics</category>
 <pubDate>Mon, 26 Jan 2009 08:43:13 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">292 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>ITIL management checklist for the optimising phase</title>
 <link>http://www.securityprocedure.com/itil-management-checklist-optimising-phase</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img385.imageshack.us/img385/9560/mgmtoptimizingchecklistyf0.jpg&quot; alt=&quot;ITIL Management Checklist&quot;&gt;&lt;/p&gt;
&lt;h3&gt;Configuration Management&lt;/h3&gt;
&lt;p&gt;As the application is reviewed within the optimise phase, is the CMDB used to assist with the review?&lt;/p&gt;
&lt;p&gt;Are Configuration Management personnel involved in the optimisation process, including providing advice in the use of and updating the inventory?&lt;/p&gt;
&lt;h3&gt;Change Management&lt;/h3&gt;
&lt;p&gt;As modifications are identified within this phase, does the team use the Change Management system to coordinate the changes?&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/itil-management-checklist-optimising-phase&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/itil-management-checklist-optimising-phase#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/checklists">Checklists</category>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/itil">ITIL</category>
 <enclosure url="http://www.securityprocedure.com/files/management-checklist-optimising-phase.xls" length="15872" type="application/vnd.ms-excel" />
 <pubDate>Thu, 01 Jan 2009 13:21:49 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">289 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Incident Management Process Flow Templates</title>
 <link>http://www.securityprocedure.com/incident-management-process-flow-templates</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img132.imageshack.us/img132/2188/incidentmanagemnetprocesm4.jpg&quot;&gt;&lt;br /&gt;
Incident Management is a sub process in ITIL that need to be implemented in every company for better IT operation. However there are a lot of concept or design that we can used to make incident management process become more simple and integrated. Above is an example of how incident management process flow would be performed&lt;/p&gt;
</description>
 <comments>http://www.securityprocedure.com/incident-management-process-flow-templates#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/incident-management">Incident Management</category>
 <category domain="http://www.securityprocedure.com/tag/itil">ITIL</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/incidentmanagementprocessflow.pdf" length="27237" type="application/pdf" />
 <pubDate>Wed, 10 Dec 2008 12:47:54 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">286 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download Backup Question Checklist Template</title>
 <link>http://www.securityprocedure.com/download-backup-question-checklist-template</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img384.imageshack.us/img384/4530/backupquestionchecklistvj3.png&quot;&gt;&lt;br /&gt;
Below some question audit checklist for backup process:&lt;/p&gt;
&lt;p&gt;What SLAs are required for this server?&lt;br /&gt;
What is the role of this server? The role will have a direct impact on the backup options and requirements for it, and will directly feed into the remaining questions to be considered for servers. Sample server roles might include production, development, test, and quality  assurance (QA).&lt;br /&gt;
Are there any special backup handling requirements for applications on the server?&lt;br /&gt;
Are there any special backup handling requirements for data on the server?&lt;br /&gt;
What times can the server be backed up?&lt;br /&gt;
What times are backups not allowed to occur?&lt;br /&gt;
What types of backups should this server receive? At minimum, most organizations will need to evaluate the necessity of the following:&lt;br /&gt;
Daily: What rotation between fulls, differentials, and incrementals are required?&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-backup-question-checklist-template&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-backup-question-checklist-template#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/backup-restore">Backup Restore</category>
 <category domain="http://www.securityprocedure.com/tag/checklists">Checklists</category>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <enclosure url="http://www.securityprocedure.com/files/BackupQuestionchecklist.xls" length="19456" type="application/vnd.ms-excel" />
 <pubDate>Mon, 01 Dec 2008 13:43:49 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">284 at http://www.securityprocedure.com</guid>
</item>
</channel>
</rss>
