<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Steal This Data &#187; infosec</title>
	<atom:link href="http://steal-this-data.com/tag/infosec/feed/" rel="self" type="application/rss+xml" />
	<link>http://steal-this-data.com</link>
	<description>A Information Security Guide for Small and Medium Sized Businesses</description>
	<lastBuildDate>Mon, 01 Dec 2008 01:19:31 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>ISO 17799: Infosec Risk Assessment Standard</title>
		<link>http://steal-this-data.com/2008/11/iso-17799-infosec-risk-assessment-standard/</link>
		<comments>http://steal-this-data.com/2008/11/iso-17799-infosec-risk-assessment-standard/#comments</comments>
		<pubDate>Sat, 29 Nov 2008 16:00:04 +0000</pubDate>
		<dc:creator>earlylit</dc:creator>
				<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[access control]]></category>
		<category><![CDATA[business continuity management]]></category>
		<category><![CDATA[communications and operations management incident management]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[iso 17799]]></category>
		<category><![CDATA[personnel security]]></category>
		<category><![CDATA[Physical Security]]></category>

		<guid isPermaLink="false">http://steal-this-data.com/?p=197</guid>
		<description><![CDATA[ISO, the International Organization for Standardization, is the world&#8217;s leading developer of International Standards, ensuring product and information interoperability. One of their most widely adopted standards is ISO/IEC 17799:2005, which establishes guidelines and general principles for initiating, implementing, maintaining, and improving information security management in an organization.&#160;This is especially important in the increasingly interconnected business [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>ISO, <a href="http://www.iso.org/iso/home.htm" target="_blank">the International Organization for Standardization</a>, is the world&rsquo;s leading developer of International Standards, ensuring product and information interoperability. One of their most widely adopted standards is ISO/IEC 17799:2005, which establishes guidelines and general principles for initiating, implementing, maintaining, and improving information security management in an organization.&nbsp;This is especially important in the increasingly interconnected business environment, where information is now exposed to a growing number and a wider variety of threats and vulnerabilities.</p>
<p>Information security is the protection of information from a wide range of threats in order to ensure business continuity, minimize business risk, and maximize return on investments and business opportunities. It is achieved by implementing a suitable set of controls, including policies, processes, procedures, organizational structures and software and hardware functions. These controls need to be established, implemented, monitored, reviewed and improved, where necessary, to ensure that the specific security and business objectives of the organization are met. This should be done in conjunction with other business management processes.</p>
<p>The objectives outlined in ISO/IEC 17799:2005 provide general guidance on the commonly accepted goals of information security management and contain best practices controls in the following areas of information security management:</p>
<ul>
<li>information security policy</li>
<li>asset management</li>
<li>human resources security</li>
<li>physical and environmental security</li>
<li>communications and operations management</li>
<li>access control</li>
<li>information systems acquisition, development and maintenance</li>
<li>information security incident management</li>
<li>business continuity management</li>
<li>compliance</li>
</ul>
<p>The control objectives and controls in ISO/IEC 17799:2005 can be used by an organization to assess the risk of doing business with partners, customers and suppliers and are a good indicator or an another organization&#8217;s IT and business process maturity.&nbsp;</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fsteal-this-data.com%2F2008%2F11%2Fiso-17799-infosec-risk-assessment-standard%2F&amp;linkname=ISO%2017799%3A%20Infosec%20Risk%20Assessment%20Standard"><img src="http://steal-this-data.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://steal-this-data.com/2008/11/iso-17799-infosec-risk-assessment-standard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Infosec Certification Guide: CompTIA</title>
		<link>http://steal-this-data.com/2008/11/infosec-certification-guide-comptia/</link>
		<comments>http://steal-this-data.com/2008/11/infosec-certification-guide-comptia/#comments</comments>
		<pubDate>Wed, 26 Nov 2008 23:46:53 +0000</pubDate>
		<dc:creator>earlylit</dc:creator>
				<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[a+ certification]]></category>
		<category><![CDATA[compTIA]]></category>
		<category><![CDATA[Computing Technology Industry Association]]></category>
		<category><![CDATA[information security certifications]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[network+ certification]]></category>
		<category><![CDATA[security+ certification]]></category>

		<guid isPermaLink="false">http://steal-this-data.com/?p=184</guid>
		<description><![CDATA[CompTIA stands for Computing Technology Industry Association. CompTia serves the IT industry as the world&#8217;s largest                     developer of vendor-neutral IT certification exams. Since             [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p><a href="http://certification.comptia.org/default.aspx" target="_blank">CompTIA stands</a> for Computing Technology Industry Association. CompTia serves the IT industry as the world&#8217;s largest                     developer of vendor-neutral IT certification exams. Since                     establishing the certification program in 1993, more than                      one million CompTIA certifications have been earned                     worldwide.</p>
<p>CompTIA currently offers three security-related certifications that can be used to satisfy the<span class="SmallText"> US Department of Defense&#8217;s (DoD) established                                              Directive 8570.1: Information Assurance                                              Training, Certification and Workforce                                              Management.</span></p>
<h4>A+ Certification</h4>
<p>The A+                 	  certification is intended for computer service technicians and validates a their ability to perform tasks such as installation, configuration,                  	  diagnosing, preventive maintenance and basic networking. The exams also cover                  	  domains such as security, safety and environmental issues and communication                 	  	  and professionalism. With more than 700,000 technicians                            certified worldwide, CompTIA A+ is seen by the                            technology community as a solid baseline credential for entry into an IT                            career.</p>
<h4>Network+ Certification</h4>
<p>The Network+ certification builds upon the A+ certification as the computer technician or IT&nbsp;networking professional acquires more work experince. This                          certification tests a technician&#8217;s ability to                          describe the features and functions of networking components                          and to install, configure and troubleshoot basic networking                          hardware, protocols and services. Although not a prerequisite,                          it is recommended that CompTIA Network+ candidates have                          at least nine months of experience in network support                          or administration or adequate academic training, along                          with a CompTIA A+ certification.</p>
<h4><span class="SmallText">Security+ Certification<br />
</span></h4>
<p>The Security+ certification builds upon the Network+ certification and tests the individual&#8217;s knowledge of systems security, network infrastructure, access control, assessments and audits, cryptography and organizational security. Although not a prerequisite, it is recommended                              that CompTIA Security+ candidates have at least two                              years of on-the-job technical networking experience, with an emphasis                              on security. The CompTIA Network+ certification is also                              recommended.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fsteal-this-data.com%2F2008%2F11%2Finfosec-certification-guide-comptia%2F&amp;linkname=Infosec%20Certification%20Guide%3A%20CompTIA"><img src="http://steal-this-data.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://steal-this-data.com/2008/11/infosec-certification-guide-comptia/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
