Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

Information Security Policies/Procedures

Welcome to the Information Security Policies/Procedures topic!

Collaborate, contribute, consume and create knowledge around various information security policies and procedures including BYOD, password complexity, and other topics.

ISACA members can participate by clicking on the “Join this Community” button. You must be signed into the site. Set your alerts to be notified of new discussion activity within this community. Not an ISACA member? Join now!

 
This Topic Has:
1233 Members
1 Online
12097 Visits

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!

Badge: Energizer

 

NEW! Activity Badges

Badges help others understand your level of community activity and your reputation as a contributor within the Knowledge Center. Learn More.

Discussions: 60 total

Must be a Topic member to contribute
View All »
Hi, does anyone have any good checklist for covering the Information Security topics in the Enterprise Architecture review process? What would be the topics to cover in the review of new systems, applications, projects from InfoSec point of view? Thank...
Juho410 | 11/7/2017 5:43:51 AM | COMMENTS(2)
Hi, does anyone have any good checklist for covering the Information Security topics in the Enterprise Architecture review process? What would be the topics to cover in the review of new systems, applications, projects from InfoSec point of view? Thank...
Juho410 | 11/7/2017 4:32:39 AM | COMMENTS(0)
All, I am looking for application security policy templates or examples that I can use to help develop one for my organization. I saw that SANS has a web application security template at: https://www.sans.org/security-resources/policies/application-securi...
Peter569 | 10/18/2017 2:24:45 PM | COMMENTS(1)
What are your recommendations for books that cover IT Policy Management?
Adora370 | 6/27/2017 8:05:59 AM | COMMENTS(0)
It's a tricky one, and from my previous post in this community you may guess has been a fascination of mine for coming on 2 decades now.   Writing policies is fine, there are many resources to help - and once you have a good set of them most auditors wil...
Daniel477 | 2/22/2017 1:42:18 AM | COMMENTS(5)
I would like to know which argument we could give for NOT having formal policies in the context of small and medium entreprises. I would like to come with other arguments than the lack of resources, or skills, which are weak arguments, in my opinion. As a...
frelem | 2/3/2017 3:57:18 PM | COMMENTS(5)

Documents & Publications: 37 total

Must be a Topic member to contribute
View All »
Posted by ISACA 903 days ago
Books
Posted by ISACA 1044 days ago
Downloads
Posted by ISACA 1206 days ago
Downloads
Posted by ISACA 1206 days ago
Downloads
Posted by ISACA 1206 days ago

Events & Online Learning: 7 total

16 Mar 2015
ISACA International Event
Orlando, FL, USA
15 Jun 2015
ISACA International Event
Ciudad de México, Mexico
1 Aug 2016
ISACA International Event
Chicago, IL, USA

Journal Articles: 34 total

Volume 3, 2107
by Jayakumar Sundaram, CISA, ISO 27001 LA
The SoA is a continuously updated and controlled document that provides an overview of information security implementation.
Volume 6, 2017
by Pedro Alexandre de Freitas Pereira, CCNA
The security of technology has become an increasing global concern. For some professionals such as network managers or security managers, this subject is intrinsically linked to their daily work.
Volume 4, 2017
by Larry G. Wlosinski, CISA, CRISC, CISM, CAP, CBCP, CCSP, CDP, CIPM, CISSP, ITIL v3, PMP
The root causes of privacy incidents include the outsourcing of data, malicious insiders, system glitches, cyberattacks, and the failure to shred or dispose of privacy data properly.
Volume 3, 2017
by Indrajit Atluri, CRISC, CISM, CEH, CISSP, CSSLP, HCISPP, ITILv3
The resolve to address IoT device security at various levels—hardware and software, government and enterprise, consumers and services—is widespread.
Volume 1, 2017
by David Eduardo Acosta R., CISA, CRISC, CISM, BS 25999 LA, CCNA Security, CEH, CHFI Trainer, CISSP Instructor, PCI QSA, OPST
Based on the information an organization manages, the security policy should set out the requirements and controls for the protection of the various assets according to their criticality
Volume 1, 2017
by David Eduardo Acosta R., CISA, CRISC, CISM, BS 25999 LA, CCNA Security, CEH, CHFI Trainer, CISSP Instructor, PCI QSA, OPST
Based on the information an organization manages, the security policy should set out the requirements and controls for the protection of the various assets according to their criticality

Wikis: 2 total

Blog Posts: 7 total

Information Security and Privacy is hot issue at present time. Number of security breaches is rapidly increasing.  In case of late detection, costs of breaches are skyrocketing. In the same time Artificial Intelligence (AI), Machine Learning (ML) are fast...
Posted By : Dragan Pleskonjic | 0 comments
My previous blog under name "Dragan on Security" was at location: http://conwex.info/blog/. It was active from August 28, 2005 to October 3, 2012. By beginning of 2017 it is moved to new location http://www.dragan-pleskonjic.com/blog/. With possibility to...
Posted By : Dragan Pleskonjic | 0 comments
Few days ago the person behind the Hacking Team hack revealed how he did it in pastebin - (the original in Spanish) https://pastebin.com/raw/GPSHF04A I was very keen to understand how good you need to be to hack back one of the most (in)famous hacki...
Posted By : TiagoRosado | 0 comments
Senior Manager           ultimate responsibility Information security Officer          functional responsibility Security Analyst           Strategic, develops policies and guidelines Owner         - Responsible for asset         - Determine level of clas...
Posted By : Muhammad554 | 0 comments
Infosec community celebrates new versions of ISO 27001:2013 and ISO 27002:2013. Worth to look at:http://blog.iso27001standard.com/2013/10/08/infographic-new-iso-27001-2013-revision-what-has-changed and everyone should read the story of genesis of  ISO 270...
Posted By : Vilius | 1 comments
13 Nov 2014
Posted By : masarker | 4 comments