Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

Information Security Policies/Procedures

Welcome to the Information Security Policies/Procedures topic!

Collaborate, contribute, consume and create knowledge around various information security policies and procedures including BYOD, password complexity, and other topics.

ISACA members can participate by clicking on the “Join this Community” button. You must be signed into the site. Set your alerts to be notified of new discussion activity within this community. Not an ISACA member? Join now!

 
This Topic Has:
777 Members
1 Online
8753 Visits

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!

Badge: Energizer

 

NEW! Activity Badges

Badges help others understand your level of community activity and your reputation as a contributor within the Knowledge Center. Learn More.

Discussions: 31 total

Must be a Topic member to contribute
View All »
HelloI need your expertise help to make a roadmap document forestablishing a new security operation center. The current security operationsfunctions are scattered in the organizationand we need to start consolidating them in one function. Ineed a referenc...
AHMED359 | 2/18/2015 11:53:47 PM | COMMENTS(3)
Should the most strict information security policies and standards from the shareholding companies be used as the baseline or can the joint-venture develop its own policies?
Robert883 | 2/12/2015 12:11:33 PM | COMMENTS(6)
I came across an interesting article which stated the 10 most relevant policies where CISO's should look at or should develop (see in https://www.infosecisland.com/blogview/5033-10-Essential-Security-Polices.html): 1 Acceptable use policy 2 Privacy po...
Marc Vael | 2/12/2015 12:05:44 PM | COMMENTS(11)
For 2015, what are the best practices or trends for CISO reporting ? To the CEO / Board / President ? To Internal Audit ? To line of business management ? To corporate risk management ? To CIO / IT executive ? To other ?
M.Lambert | 2/12/2015 2:47:54 AM | COMMENTS(3)
I'm in the process of reviewing our internal and external IT Security policies and would like some guidance on this.My question is whether you start by performing a gap analysis of the current policies, looking at their effectiveness by the amount of exce...
Peter S | 2/12/2015 12:17:19 AM | COMMENTS(3)
This week one of our company websites was copied to a slightly different URL, with the contact details altered.  Is is it possible to technically prevent such or at least make it more difficult to copy the content?
Robert883 | 2/11/2015 10:09:56 PM | COMMENTS(4)

Documents & Publications: 51 total

Must be a Topic member to contribute
View All »
Books
Posted by ISACA 29 days ago
Books
Posted by ISACA 77 days ago
Downloads
Posted by ISACA 191 days ago
Downloads
Posted by ISACA 191 days ago
Downloads
Posted by ISACA 191 days ago

Events & Online Learning: 8 total

14 Oct 2013
ISACA International Event
Boston, MA, USA
16 Jun 2014
ISACA International Event
Seattle, WA, USA
11 Aug 2014
ISACA International Event
Seattle, WA, USA
16 Mar 2015
ISACA International Event
Orlando, FL, USA

Journal Articles: 126 total

Volume 2, 2015
by Kerry A. Anderson, CISA, CISM, CGEIT, CRISC, CCSK, CFE, CISSP, CSSLP, ISSAP, ISSMP
One of biggest budget busters for an information security program is technology solutions that are not a good match for the organization.
Volume 2, 2015
by Mauricio Rocha Lyra, Ph.D., COBIT Foundation, CTFL, ISO 20000, ITIL, MCSO, OCUP, PMP, RUP and Jose Carlos Ferrer Simoes
The transformations experienced by organizations due to technological advances has made information, arguably, an enterprise’s most valuable asset.
Volume 6, 2014
by Jeimy J. Cano M., Ph.D, CFE
International trends reflect a paradigmatic change in current business models caused by the markets’ asymmetry and dynamics where instability is the constant and change is the norm.
Volume 5, 2014
by Ed Gelbstein, Ph.D.
There are three domains that impact information security.
Volume 2, 2014
by James Baird, CISM, CISSP, ISO 27001 LI, ITIL (F)
There is an axiom for authors that states to be a successful writer, one must know the reader.
Volume 2, 2014
by Key Mak, CISM, CAP, CISSP, ITIL, PMP, Security Plus, ECMp
Whether launching an information security project or developing a road map for an enterprise, determining where to start can be overwhelming.

Wikis: 2 total

Blog Posts: 3 total

Must be a Topic member to view blog posts
Infosec community celebrates new versions of ISO 27001:2013 and ISO 27002:2013. Worth to look at:http://blog.iso27001standard.com/2013/10/08/infographic-new-iso-27001-2013-revision-what-has-changed and everyone should read the story of genesis of  ISO 270...
Posted By : Vilius | 1 comments
13 Nov 2014
Posted By : masarker | 4 comments
On March 1st,  I was invited to speak at the CampIT conference on Enterprise Risk/Security Management at Rosemont Convention Center. Before me there were two speakers. The first presenter spent an hour presenting the story from the trenches of technolog...
Posted By : Umesh391 | 2 comments