Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

NEW! Participate in Discussions Via Email. 

You can now respond to discussions by simply replying to the email alert. Just enable this feature in discussions on this topic. Learn more

Recent Discussions

Security Management at INSIGHTS 2013

Hi all,at INSIGHTS 2013 (http://www.isaca.org/Education/Conferences/Pages/INSIGHTS-2013.aspx) the t...

Marc Vael @ 4/12/2013 4:36 AM | Comments (0)

Relationship between IT Audit ad Information Security

Greetings!I need some advice since my searches have not come up with much just yet.Does anyone know...

edward352 @ 4/7/2013 9:09 AM | Comments (0)

Brand new book about Security Management "C(I)SO - And Now What"

Hello Thought Leaders - I have published a new book for exactly our group (title: "C(I)SO - An...

Michael S. Oberlaender @ 4/5/2013 12:52 PM | Comments (0)

Setting up an Information Security Department

Hi, I am setting up a new information security department in a fairly young technical University an...

Benjamin715 @ 4/1/2013 10:37 AM | Comments (2)

2013 IT Risk Management Whitepaper

IT RISK MANAGEMENTDRIVERS, CHALLENGES AND ENABLERS FOR AUSTRALIANORGANISATIONS To attain strategic,...

Paras_Shah @ 3/22/2013 7:01 AM | Comments (0)

Allowing Employees to install software/programs

I'm after some advice please...Should companies allow their employees to be able to install softwar...

Martin111 @ 3/21/2013 4:31 AM | Comments (0)

ISO 27001 Policy audits

HiFor those who have experience of ISO 27001 Accreditation audits can you tell me if the auditors a...

Len Shingler @ 2/21/2013 11:20 AM | Comments (3)

Technical and Infosec Reporting

I’m looking for some advice and opinion on what makes a good, and by good I mean targeted Technical...

Mark Conabeare @ 1/9/2013 12:11 PM | Comments (1)

How to align between IT Audit, IT Assurance and Information Security(Infosec)

Hello, all. I would really like to get/have your expert view on this title. Lets say in an organisa...

Taty @ 9/11/2012 1:17 AM | Comments (3)

EUROCACS 2012 topic "information security tug of war"

Hi all,Please welcome Wendy Goucher to the InformationSecurity Management topic. Wendy will be pres...

Marc Vael @ 8/16/2012 4:44 PM | Comments (1)

CISA or CISM which one should I go for?

I am currently pursuing MS in Information Security. I have no work experience.Now I want to do a ce...

Rahul Das @ 6/30/2012 1:35 AM | Comments (5)

Lesson Learned from the Linkedin Debacle

"Just like theYahoo CEO with a lie on his resume, the linkedin example is a entertaining, beca...

AMBACISA @ 6/13/2012 6:49 PM | Comments (1)

LINKEDIN PASSWORD FAILURE

Based on the recent news that 6,458,020 hashed Linkedin passwords were uploaded, what do you recomm...

Marc Vael @ 6/7/2012 4:57 AM | Comments (1)

Dual Authentication Fine Line

Hi AllI am interested in what people think about Dual Authentication.What would you define as dual ...

DMLewis @ 4/19/2012 8:13 AM | Comments (1)

Burnout risk with security professionals increases

A recent survey of stress levels among IT security staff has shown that an alarming number of staff...

Marc Vael @ 2/28/2012 7:24 AM | Comments (1)

RE: Setting up an Information Security Department

Thanks Charla,I just joined the group. Thanks for the pointer

Benjamin715 @ 6/14/2013 3:44 AM

RE: Setting up an Information Security Department

Benjamin - I would recommend that you join Educause if you are not already a member, and get connec...

Charla Berry @ 6/12/2013 2:18 PM

RE: ISO 27001 Policy audits

Few points to consider: 1) The certification auditor is bound to restrict area to assess for the sc...

Paras_Shah @ 3/22/2013 7:00 AM

RE: ISO 27001 Policy audits

I agree with Marc's comments above and I would also say that in my experience you also need to work...

Chris @ 3/19/2013 3:36 PM

RE: How to align between IT Audit, IT Assurance and Information Security(Infosec)

Well said by everyone. I am a Systems Auditor in an organisation that has within a broader departme...

Tipho217 @ 3/12/2013 9:27 AM

RE: ISO 27001 Policy audits

Very good and practical question. In practice, experienced ISO27001 auditors will start of by looki...

Marc Vael @ 2/28/2013 2:47 PM

RE: Technical and Infosec Reporting

Very relevant topic/question.Indeed, too many reports are staying too technical to understand for m...

Marc Vael @ 2/15/2013 1:30 PM

EUROCACS 2012 topic "information security tug of war"

All presentations can be found on http://www.isaca.org/Education/Conferences/Pages/European-CACS-IS...

Marc Vael @ 12/11/2012 9:16 AM

Ask your information security mgt question via email

Dear members, from now on we guarantee a reply with content within 48hours on this ISACA COMMUNITY.

Marc Vael @ 12/11/2012 9:14 AM

difference in maturity levels between information Security management in public sector and private sector organisations

Difficult to proove. A lot of perception issues and stereotypes would reign. As always "it dep...

Marc Vael @ 12/11/2012 9:07 AM

Security testing by hackers

More information on LulzSec can be found on http://en.wikipedia.org/wiki/LulzSec

Marc Vael @ 12/11/2012 9:05 AM

Will cloud computing change organizations?

All results can be found on http://www.isaca.org/cloud

Marc Vael @ 12/11/2012 9:04 AM

Applying BMIS in practice

ITIL and COBIT5 www.itil.se/itilse_documents/COBIT5-and-InfoSec.ppt

Marc Vael @ 12/11/2012 9:02 AM

BMIS security model and COBIT5

More information can be found on www.itil.se/itilse_documents/COBIT5-and-InfoSec.ppt

Marc Vael @ 12/11/2012 9:01 AM

Cybersecurity Workforce Development

Thanks. Very nice. In December 2010 following report was published http://www.sei.cmu.edu/library/a...

Marc Vael @ 12/11/2012 9:00 AM

If a company wants to donate PC's to a charity, what is the right procedure for deleting all data?

A question started byAbbas Kudrati, Head - Quality & Information Security Standard at eGovernme...

Marc Vael @ 6/15/2010 8:45 AM | Comments (6)

Is gamification a solution for the information security awareness?

Hype or not, gamification becomes a professional solution which expands out of the entertainment an...

Marc Vael @ 1/5/2012 12:09 PM | Comments (6)

CISA or CISM which one should I go for?

I am currently pursuing MS in Information Security. I have no work experience.Now I want to do a ce...

Rahul Das @ 6/30/2012 1:35 AM | Comments (5)

Information Security Governance: Why Is it Not More Prevasive?

I am an avid believer in the concept of information security governance, and I believe this concept...

Eugene510 @ 8/24/2010 1:20 PM | Comments (5)

New to IS Management

I have just been given responsibility for Information Security Management within my organisation.  ...

PHolmes @ 6/17/2011 9:47 AM | Comments (4)

Greetings, and A Challenge to Our Members

Greetings to everyone who has joined our group for Information Security Management.  On behalf of I...

David Scott @ 11/16/2011 4:12 PM | Comments (4)

How to align between IT Audit, IT Assurance and Information Security(Infosec)

Hello, all. I would really like to get/have your expert view on this title. Lets say in an organisa...

Taty @ 9/11/2012 1:17 AM | Comments (3)

ISO 27001 Policy audits

HiFor those who have experience of ISO 27001 Accreditation audits can you tell me if the auditors a...

Len Shingler @ 2/21/2013 11:20 AM | Comments (3)

Log Management Products

Hello group members! Does anyone know if Snare (open-source log management tool) will work in conju...

Charla Berry @ 7/20/2010 11:33 AM | Comments (3)

Cloud Computing & Security Management

Is cloud computing enhancing or worsening the security management for a company?

Marc Vael @ 6/10/2010 9:47 AM | Comments (3)

Reading recommendations?

Having moved relatively recently from IT Audit to Information Security, I'm looking to read around ...

Matt @ 1/17/2011 1:19 PM | Comments (3)

Secure Web Coding Practices - White Paper

ISACA is looking to our certified professionals to assist in the creation of a white paper that wil...

Russ Wolfe @ 4/20/2011 9:26 AM | Comments (3)

Cost-effective identity management in practice

1.) How did you implement a cost-effective - reduced budget - identity management solution?2.) What...

Vilmos Csuri @ 6/12/2010 6:19 AM | Comments (2)

Auditors and IS Security Professionals

I  just attended a symposium by information security professionals this week and listened to one of...

Pautsang @ 10/22/2010 4:42 PM | Comments (2)

Certification Statistics

With an even increasing demand for professionals in the Information Security Management space, work...

danielperez @ 2/6/2012 6:03 PM | Comments (2)