<?xml version="1.0" encoding="utf-8"?><rss version="2.0"><channel><title>JOnline Rss Feed</title><link>http://www.isaca.org/_layouts/feed.aspx?xsl=1&amp;web=/Journal/JOnline&amp;page=1f9083b8-c09b-4ec0-b6b8-2aa6afcea298&amp;wp=2af0a82c-ffec-411c-bd62-e82338f94d5b</link><description>JOnline Rss Feed</description><ttl>60</ttl><item><title>JOnline: Phishing Should Not be Treated the Same as Common Spam</title><link>http://www.isaca.org/Journal/Past-Issues/2013/Volume-3/Pages/JOnline-Phishing-Should-Not-be-Treated-the-Same-as-Common-Spam.aspx</link><description>In the US alone, phishing attacks on customers have been reported to result in direct financial losses of several billion US dollars per year.</description><pubDate>Wed, 29 May 2013 19:22:09 GMT</pubDate></item><item><title>JOnline: An Introduction to Auditing HP NonStop Servers—Review of User Access</title><link>http://www.isaca.org/Journal/Past-Issues/2013/Volume-3/Pages/JOnline-An-Introduction-to-Auditing-HP-NonStop-Servers-Review-of-User-Access.aspx</link><description>This article presents an overview of the key principles used to audit an HP NonStop system.</description><pubDate>Wed, 29 May 2013 19:21:43 GMT</pubDate></item><item><title>JOnline: Dealing With Computer Fraud</title><link>http://www.isaca.org/Journal/Past-Issues/2013/Volume-3/Pages/JOnline-Dealing-With-Computer-Fraud.aspx</link><description>As all organisations have become increasingly automated, their IT has become critical. </description><pubDate>Wed, 29 May 2013 19:21:53 GMT</pubDate></item><item><title>JOnline: The Information Systems Auditor Unmasked</title><link>http://www.isaca.org/Journal/Past-Issues/2013/Volume-2/Pages/JOnline-The-Information-Systems-Auditor-Unmasked.aspx</link><description>This article guides the IT professional through the mind and methodology of the IS auditor with a specific focus on procedures performed by external auditors.</description><pubDate>Thu, 28 Mar 2013 21:37:03 GMT</pubDate></item><item><title>JOnline: The Extent of Corporate Social Responsibility</title><link>http://www.isaca.org/Journal/Past-Issues/2013/Volume-2/Pages/JOnline-The-Extent-of-Corporate-Social-Responsibility.aspx</link><description>Why are organizations instituting corporate social responsibility (CSR) programs?</description><pubDate>Thu, 28 Mar 2013 21:36:31 GMT</pubDate></item><item><title>JOnline: Improving Governance Models</title><link>http://www.isaca.org/Journal/Past-Issues/2013/Volume-2/Pages/JOnline-Improving-Governance-Models.aspx</link><description>This article discusses the benefits of using the framework of the five IT governance focus areas.</description><pubDate>Thu, 28 Mar 2013 21:36:44 GMT</pubDate></item><item><title>JOnline: Convenient Quality Control for IT Governance-aware Enterprises</title><link>http://www.isaca.org/Journal/Past-Issues/2013/Volume-1/Pages/Convenient-Quality-Control-for-IT-Governance-aware-Enterprises.aspx</link><description>Since IT processes are at the heart of the business life, creating more effective and efficient processes results in achievement of business objectives.</description><pubDate>Thu, 31 Jan 2013 19:56:57 GMT</pubDate></item><item><title>JOnline: Using Personal Mobile Devices in a Business Setting</title><link>http://www.isaca.org/Journal/Past-Issues/2013/Volume-1/Pages/Using-Personal-Mobile-Devices-in-a-Business-Setting.aspx</link><description>Risk exists with the implementation of personal mobile devices in business, but with risk comes reward.</description><pubDate>Thu, 31 Jan 2013 19:57:12 GMT</pubDate></item><item><title>JOnline: BYOD in the Enterprise—A Holistic Approach</title><link>http://www.isaca.org/Journal/Past-Issues/2013/Volume-1/Pages/BYOD-in-the-Enterprise-A-Holistic-Approach.aspx</link><description>This article provides insights on BYOD, its implication to IT and how organizations need to approach and adopt it. </description><pubDate>Thu, 31 Jan 2013 19:56:43 GMT</pubDate></item><item><title>JOnline: Security Metrics—A Beginner’s Guide</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-6/Pages/JOnline-Security-Metrics-A-Beginners-Guide.aspx</link><description>Security metrics are important not only for claiming the optimum share of IT budget, but also for creating security awareness across the company and improving the overall security posture of the organization.</description><pubDate>Thu, 29 Nov 2012 20:35:36 GMT</pubDate></item><item><title>JOnline: A Strategic Framework for IT Disaster Recovery Assessments</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-6/Pages/JOnline-A-Strategic-Framework-for-IT-Disaster-Recovery-Assessments.aspx</link><description>This article presents a practice-tested framework that structures and prioritizes the assessment of DR programs, testing the most business-critical aspects first.</description><pubDate>Thu, 29 Nov 2012 20:35:26 GMT</pubDate></item><item><title>JOnline: Is the Business Network Connected to SCADA? Need for Auditing SCADA Networks</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-6/Pages/JOnline-Is-the-Business-Network-Connected-to-SCADA.aspx</link><description>The integration or connection of SCADA networks to business networks is more necessary than ever before.</description><pubDate>Thu, 29 Nov 2012 20:35:32 GMT</pubDate></item><item><title>JOnline: An Introduction to Crisis Management</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-5/Pages/JOnline-An-Introduction-to-Crisis-Management.aspx</link><description>Risk that is not identified, or at least not identified with the scale and intensity it presents, can produce a crisis.</description><pubDate>Thu, 27 Sep 2012 19:36:17 GMT</pubDate></item><item><title>JOnline: Identity Mining and Insider Threat Monitoring</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-5/Pages/JOnline-Identity-Mining-and-Insider-Threat-Monitoring.aspx</link><description>This article reviews the definition of an insider threat and its impact, and provides an overview of the techniques to control and remediate these threats. </description><pubDate>Mon, 15 Oct 2012 19:30:38 GMT</pubDate></item><item><title>JOnline: Réseaux Sociaux et Vie Privée: Menaces et Protections</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-5/Pages/JOnline-Social-Networks-and-Privacy-Threats-and-Protection-French.aspx</link><description>Cet article a un double objectif: partir des motivations des Internautes à fréquenter les réseaux sociaux en vue d’identifier le risque de violation de leur vie privée, et d’analyser et évaluer l’efficacité des moyens de contrôle de lutte mis en œuvre.</description><pubDate>Thu, 27 Sep 2012 19:37:08 GMT</pubDate></item><item><title>JOnline: To Click or Not to Click? That Is the Question</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-4/Pages/JOnline-To-Click-or-Not-to-Click-That-Is-the-Question.aspx</link><description>Information security awareness training courses are delivered every day in many companies, yet the results are often not as good as expected. </description><pubDate>Wed, 01 Aug 2012 14:19:34 GMT</pubDate></item><item><title>JOnline: El Negocio de la Seguridad de la Información: Revelando la Potencialidad de un Concepto</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-4/Pages/JOnline-El-Negocio-de-la-Seguridad-de-la-Informacion-Revelando-la-Potencialidad-de-un-Concepto.aspx</link><description>Tener claridad sobre el modelo de negocio que se desarrolla en una organización es encontrar la fuente de la sabiduría empresarial.</description><pubDate>Wed, 01 Aug 2012 14:16:01 GMT</pubDate></item><item><title>JOnline: 10 Key Rules for Using the ITIL Framework Effectively</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-4/Pages/JOnline-10-Key-Rules-for-Using-the-ITIL-Framework-Effectively.aspx</link><description>This article shares some of the practical challenges in IT service management (ITSM) and how the ITIL framework can be used to overcome those challenges.</description><pubDate>Wed, 01 Aug 2012 14:17:48 GMT</pubDate></item><item><title>JOnline: Transitioning From SAS 70 to SSAE 16</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-3/Pages/JOnline-Transitioning-From-SAS-70-to-SSAE-16.aspx</link><description>This article highlights the need for SSAE 16, the notable differences and similarities between SSAE 16 and SAS 70, and estimates the effort required to transition to the new standard</description><pubDate>Fri, 08 Jun 2012 15:08:31 GMT</pubDate></item><item><title>JOnline: Book Review—The Operational Risk Handbook for Financial Companies</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-3/Pages/JOnline-Book-Review-The-Operational-Risk-Handbook-for-Financial-Companies.aspx</link><description>In the last years, it has become more and more evident that there is a growing gap between taking financial risk and the liability for taking risk.</description><pubDate>Fri, 08 Jun 2012 15:07:44 GMT</pubDate></item><item><title>JOnline: Book Review—Security, Audit and Control Features Oracle PeopleSoft, 3rd Edition</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-3/Pages/JOnline-Book-Review-Security-Audit-and-Control-Features-Oracle-PeopleSoft-3rd-Edition.aspx</link><description>Oracle PeopleSoft HCM is one of the most commonly used human capital management (HCM) system found in medium to large companies in the US.</description><pubDate>Fri, 08 Jun 2012 15:18:49 GMT</pubDate></item><item><title>JOnline: Book Review—Master Data Management and Data Governance</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-2/Pages/JOnline-Master-Data-Management-and-Data-Governance.aspx</link><description>This book is a reference guide that looks at the topics of MDM and data governance from multiple perspectives.</description><pubDate>Mon, 02 Apr 2012 13:22:41 GMT</pubDate></item><item><title>JOnline: Testing Your Computer Security Incident Response Plan</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-2/Pages/JOnline-Testing-Your-Computer-Security-Incident-Response-Plan.aspx</link><description>This article discusses the genesis for CSIR testing, several testing methodologies and/or exercises with which an organization can assess the maturity of its CSIR plan/program.</description><pubDate>Wed, 11 Apr 2012 18:54:23 GMT</pubDate></item><item><title>JOnline: Customer Relationship Information Technology Internal Control and Security Framework</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-2/Pages/JOnline-Customer-Relationship-Information-Technology-Internal-Control-and-Security-Framework.aspx</link><description>This article first describes the benefits of CRM systems and identifies risk areas inherent in CRM systems that threaten the benefits an organization can receive from a CRM system.</description><pubDate>Mon, 02 Apr 2012 13:23:00 GMT</pubDate></item><item><title>JOnline: Book Review—Information Security and Privacy</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-1/Pages/JOnline-Book-Review-Information-Security-and-Privacy.aspx</link><description>It is critical for businesses to understand legal implications and compliance and to have appropriate safeguards and risk management efforts in place to protect the information and private data of customers and the organization.</description><pubDate>Mon, 30 Jan 2012 19:07:20 GMT</pubDate></item><item><title>JOnline: Book Review—Cyber Attacks: Protecting National Infrastructure</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-1/Pages/JOnline-Book-Review-Cyber-Attacks-Protecting-National-Infrastructure.aspx</link><description>This book is particularly interesting to and useful for information security and IT governance professionals because of its strategic and tactical guidance that can help refine decisions on the protection of critical infrastructure.</description><pubDate>Mon, 30 Jan 2012 19:08:28 GMT</pubDate></item><item><title>JOnline: Log Management: A Pragmatic Approach to PCI DSS</title><link>http://www.isaca.org/Journal/Past-Issues/2012/Volume-1/Pages/JOnline-Log-Management-A-Pragmatic-Approach-to-PCI-DSS.aspx</link><description>Log management can play a pivotal role in addressing PCI DSS requirements, be a success factor and enabler for safeguarding cardholder transaction data, and provide a secure and vulnerability-free environment for cardholders.</description><pubDate>Wed, 01 Feb 2012 14:57:10 GMT</pubDate></item><item><title>JOnline: Identity and Access Management—Its Role in Sarbanes-Oxley Compliance</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-6/Pages/JOnline-Identity-and-Access-Management-Its-Role-in-Sarbanes-Oxley-Compliance.aspx</link><description>As today’s business climate demands greater efficiency, security and regulatory compliance, the need for an effective IAM process has never been more pressing.</description><pubDate>Thu, 01 Dec 2011 15:55:51 GMT</pubDate></item><item><title>JOnline: Clearing the Cloud Over PCI DSS v2.0</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-6/Pages/JOnline-Clearing-the-Cloud-Over-PCI-DSS-v2-0.aspx</link><description>This article is intended to showcase the changes made to PCI DSS v2.0 over v1.2 to further assist with detailed understanding of the control requirements to facilitate the PCI compliance process.</description><pubDate>Thu, 01 Dec 2011 15:57:29 GMT</pubDate></item><item><title>JOnline: An Introduction to Information Security Incident Management Based on ISO/IEC TR 18044:2004</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-6/Pages/JOnline-An-Introduction-to-Information-Security-Incident-Management-Based-on-ISO-IEC-TR-18044-2004.aspx</link><description>The main objective of this article is to provide an overview of information security incident management based on ISO/IEC TR 18044:2004.</description><pubDate>Thu, 01 Dec 2011 15:59:15 GMT</pubDate></item><item><title>JOnline: An Introduction to Information Security Management in Health Care Organizations</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-5/Pages/JOnline-An-Introduction-to-Information-Security-Management-in-Health-Care-Organizations.aspx</link><description>The main objective of this article is to provide an introduction to the key elements of information security management in health care using ISO 27799:2008.</description><pubDate>Mon, 14 Nov 2011 21:30:55 GMT</pubDate></item><item><title>JOnline: La Gerencia de la Seguridad de la Información: Evolución y Retos Emergentes</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-5/Pages/JOnline-La-Gerencia-de-la-Seguridad-de-la-Informacion-Evolucion-y-Retos-Emergentes.aspx</link><description>Asegurar una efectiva estrategia de seguridad de la información, no es sólo cuestión de instalar y mantener artefactos tecnológicos especializados.</description><pubDate>Mon, 03 Oct 2011 14:45:45 GMT</pubDate></item><item><title>JOnline: Certification—The Answer to Cybersecurity Woes?</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-5/Pages/JOnline-Certification-The-Answer-to-Cybersecurity-Woes.aspx</link><description>Organizations need fully articulated security policies and procedures based on industry best practices to solidify their information system defenses and meet legal, contractual and regulatory requirements.</description><pubDate>Mon, 03 Oct 2011 14:45:23 GMT</pubDate></item><item><title>JOnline: The Influence of Irrelevant Information on IS Auditor Key Risk Factor Predictions</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-4/Pages/JOnline-The-Influence-of-Irrelevant-Information-on-IS-Auditor-Key-Risk-Factor-Predictions.aspx</link><description>The results of this study reveal that IS auditors’ KRF assessments are significantly lower when irrelevant information is present vs. when irrelevant information is not present.</description><pubDate>Fri, 29 Jul 2011 17:34:07 GMT</pubDate></item><item><title>JOnline: Impact of Security Awareness Training Components on Perceived Security Effectiveness</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-4/Pages/JOnline-Impact-of-Security-Awareness-Training-Components-on-Perceived-Security-Effectiveness.aspx</link><description>Security awareness training is a vital nontechnical component to information security. </description><pubDate>Fri, 29 Jul 2011 17:33:15 GMT</pubDate></item><item><title>JOnline: BMIS—An Introduction to the System Environment</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-4/Pages/JOnline-BMIS-An-Introduction-to-the-System-Environment.aspx</link><description>BMIS takes a business-oriented approach to managing information security.</description><pubDate>Fri, 29 Jul 2011 17:32:09 GMT</pubDate></item><item><title>JOnline: Book Review: Fraud Auditing and Forensic Accounting, 4th Edition</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-3/Pages/Fraud-Auditing-and-Forensic-Accounting-4th-Edition.aspx</link><description>The mission of this book is to provide a comprehensive textbook filled with knowledge, experience and methodologies for the financial auditor, fraud auditor and forensic accountant.</description><pubDate>Tue, 07 Feb 2012 16:49:11 GMT</pubDate></item><item><title>JOnline: An Introduction to Incident Preparedness and Operational Continuity Management Based on ISO/PAS 22399:2007</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-3/Pages/An-Introduction-to-Incident-Preparedness-and-Operational-Continuity-Management-Based-on-ISO-PAS-22399-2007.aspx</link><description>The main objective of this article is to provide an introduction to the key elements of IPOCM, based on ISO/PAS 22399:2007.</description><pubDate>Tue, 07 Feb 2012 16:48:28 GMT</pubDate></item><item><title>JOnline: Top IT Governance Issues of 2011</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-3/Pages/Top-IT-Governance-Issues-of-2011.aspx</link><description>This article seeks to identify a tentative list of the most prominent issues that are impacting stakeholders in the governance space in 2011.</description><pubDate>Tue, 07 Feb 2012 16:49:51 GMT</pubDate></item><item><title>JOnline: El Debido Cuidado en Seguridad de la Información</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-2/Pages/El-Debido-Cuidado-en-Seguridad-de-la-Informacion.aspx</link><description>Las consecuencias de las fallas frente a la protección de la información en las organizaciones frecuentemente terminan en pérdidas de disponibilidad y en efectos, algunas veces catastróficos.</description><pubDate>Fri, 10 Feb 2012 18:38:41 GMT</pubDate></item><item><title>JOnline: The Prevalence of Information Security Controls: Perspectives From IT Auditors</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-2/Pages/The-Prevalence-of-Information-Security-Controls-Perspectives-From-IT-Auditors.aspx</link><description>Among the various organizational, technological and operational controls outlined in ISO 27002, what security controls are the most commonly implemented?</description><pubDate>Tue, 07 Feb 2012 17:17:58 GMT</pubDate></item><item><title>JOnline: Mapping PCI DSS v2.0 With COBIT 4.1</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-2/Pages/Mapping-PCI-DSS-v20-With-COBIT41.aspx</link><description>This article contains the results of a mapping of Payment Card Industry Data Security Standard (PCI DSS) v2.0 controls with COBIT 4.1.</description><pubDate>Tue, 07 Feb 2012 17:17:23 GMT</pubDate></item><item><title>JOnline: The Relevance of IT in Criminal Investigations</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-1/Pages/The-Relevance-of-IT-in-Criminal-Investigations.aspx</link><description>The main objective of this article is to point out some of the specifics and problems of expert testimony in the field of IT.</description><pubDate>Tue, 07 Feb 2012 17:36:03 GMT</pubDate></item><item><title>JOnline: Risk Management When Implementing ERP Systems</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-1/Pages/Risk-Management-When-Implementing-ERP-Systems.aspx</link><description>This article focuses on the types of risk advisory services that are common during an ERP implementation.</description><pubDate>Tue, 07 Feb 2012 17:35:24 GMT</pubDate></item><item><title>JOnline: Auditing Biometrics-based Authentication Systems</title><link>http://www.isaca.org/Journal/Past-Issues/2011/Volume-1/Pages/Auditing-Biometrics-based-Authentication-Systems.aspx</link><description>This article aims to describe nuances of biometric authentication methods that will help the audit community.</description><pubDate>Tue, 07 Feb 2012 17:34:48 GMT</pubDate></item><item><title>JOnline: Book Review—Computer Security, Privacy, and Politics: Current Issues, Challenges, and Solutions</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-6/Pages/Computer-Security-Privacy-and-Politics.aspx</link><description>This book connects privacy and politics, offering a point-in-time review of recent developments in computer security.</description><pubDate>Tue, 19 Mar 2013 19:15:34 GMT</pubDate></item><item><title>JOnline: Information Security Automation: The Second Wave</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-6/Pages/Information-Security-Automation-The-Second-Wave.aspx</link><description>This article presents a simplified approach to IT security management that allows IT auditors and information security professionals to discharge their responsibilities more efficiently.</description><pubDate>Tue, 07 Feb 2012 17:50:50 GMT</pubDate></item><item><title>JOnline: Emergency Access Controls in SAP Environments</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-6/Pages/Emergency-Access-Controls-in-SAP-Environments.aspx</link><description>This article provides an overview of the tools and solutions to consider when establishing acceptable IT practices to address the challenge that emergency access to SAP environments poses.</description><pubDate>Tue, 07 Feb 2012 17:49:31 GMT</pubDate></item><item><title>JOnline: Privacy and Security Considerations for EHR Incentives and Meaningful Use</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-5/Pages/Privacy-and-Security-Considerations-for-EHR-Incentives-and-Meaningful-Use.aspx</link><description>This article focuses on the privacy and security aspects of the HITECH Act portion of the US American Recovery and Reinvestment Act, EHR certification criteria, and standards included in meaningful use.</description><pubDate>Tue, 07 Feb 2012 18:09:02 GMT</pubDate></item><item><title>JOnline: Evolution of Federal Cybersecurity—From Individual Controls to Systems of Control</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-5/Pages/Evolution-of-Federal-Cybersecurity-From-Individual-Controls-to-Systems-of-Control.aspx</link><description>This article discusses what is needed to address the recent NIST SP 800-53 requirement changes and to build greater value delivery and extract more cost-effective management controls.</description><pubDate>Tue, 07 Feb 2012 18:06:53 GMT</pubDate></item><item><title>JOnline: Health Care Reform Legislation Survival Guide, Part 2</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-5/Pages/Health-Care-Reform-Legislation-Survival-Guide-Part2.aspx</link><description>This article discusses the US Department of Health and Human Services Health Breach Notification Rule:  Final Rule.</description><pubDate>Tue, 07 Feb 2012 18:08:15 GMT</pubDate></item><item><title>JOnline: Fundamentals of IT Governance Based on ISO/IEC 38500</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-5/Pages/Fundamentals-of-IT-Governance-Based-on-ISOIEC-38500.aspx</link><description>This article provides an introduction to the key elements of IT governance, to key industry frameworks used by organizations, and to guiding principles for directors of organizations on the use of IT based on ISO/IEC 38500:2008.</description><pubDate>Tue, 07 Feb 2012 18:07:35 GMT</pubDate></item><item><title>JOnline: Auditing Electronic Auction Systems</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-4/Pages/JOnline-Auditing-Electronic-Auction-Systems.aspx</link><description>The purpose of this article is to highlight the nature of the various risks inherent in electronic auctions and to outline some controls to prevent and/or mitigate these risks.</description><pubDate>Tue, 07 Feb 2012 18:20:06 GMT</pubDate></item><item><title>JOnline: Using Microsoft Office in Analyzing SAP SoD and Beyond</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-4/Pages/JOnline-Using-Microsoft-Office-in-Analyzing-SAP-SoD-and-Beyond.aspx</link><description>Properly assessing SoD has increasingly become a challenge in today’s businesses, due to increasing reliance on complicated information systems and deficient knowledge of the new forms of risks posed by computerized business processes.</description><pubDate>Tue, 07 Feb 2012 18:21:37 GMT</pubDate></item><item><title>JOnline: Security of Industrial Control Systems</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-4/Pages/JOnline-Security-of-Industrial-Control-Systems.aspx</link><description>The purpose of this article is to summarize the major cybersecurity issues of ICS to help improve awareness among owners, (security) professionals, auditors and policy makers and to help organizations recognize threats and vulnerabilities.</description><pubDate>Tue, 07 Feb 2012 18:20:52 GMT</pubDate></item><item><title>JOnline: An Introduction to the Privacy Impact Assessment Based on ISO 22307</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-4/Pages/JOnline-An-Introduction-to-the-Privacy-Impact-Assessment-Based-on-ISO22307.aspx</link><description>This article focuses and comments on the ISO privacy standard and PIA in general.</description><pubDate>Tue, 07 Feb 2012 18:19:20 GMT</pubDate></item><item><title>JOnline: Making Sure You Really Are Walking on Cloud Nine</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-3/Pages/JOnline-Making-Sure-You-Really-Are-Walking-on-Cloud-Nine.aspx</link><description>This article explores common-sense strategies to ensure an organization’s cloud computing endeavors are successful and unproblematic.</description><pubDate>Tue, 07 Feb 2012 18:38:34 GMT</pubDate></item><item><title>JOnline: Book Review—IT Outsourcing Part 1: Contracting the Partner—A Management Guide</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-3/Pages/JOnline-IT-Outsourcing-Part1-Contracting-the-Partner.aspx</link><description>This book is a how-to guide and practical key reference of best practices for the creation of a request for proposal (RFP) for the outsourcing of IT services as a strategic business alternative. </description><pubDate>Tue, 19 Mar 2013 20:20:43 GMT</pubDate></item><item><title>JOnline: Tackling Cybercrime: Divide and Conquer</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-3/Pages/JOnline-Tackling-Cybercrime-Divide-and-Conquere.aspx</link><description>This article will analyze the malware situation and outline an economic model. Based on this model, the consequences of software diversification are described, with some recommendations to implement this security measure.</description><pubDate>Tue, 07 Feb 2012 18:39:12 GMT</pubDate></item><item><title>JOnline: Realizing Benefits of IT Investments: Overcoming the Silver-bullet View</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-2/Pages/JOnline-Realizing-Benefits-of-IT-Investments.aspx</link><description /><pubDate>Tue, 07 Feb 2012 18:57:21 GMT</pubDate></item><item><title>JOnline: The Failure of Risk Management: Why It’s Broken and How to Fix It</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-2/Pages/JOnline-The-Failure-of-Risk-Management.aspx</link><description /><pubDate>Tue, 07 Feb 2012 18:58:40 GMT</pubDate></item><item><title>JOnline: Application Security Using the Role-based Access Control Model</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-2/Pages/JOnline-Application-Security-Using-the-Role-based-Access-Control-Model.aspx</link><description /><pubDate>Tue, 07 Feb 2012 18:56:39 GMT</pubDate></item><item><title>JOnline: Realizing Trustworthy Business Services Through a New GRC Approach</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-2/Pages/JOnline-Realizing-Trustworthy-Business-Services-Through-a-New-GRC-Approach.aspx</link><description /><pubDate>Tue, 07 Feb 2012 18:58:00 GMT</pubDate></item><item><title>JOnline: Gobierno de las TIC ISO/IEC 38500</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-1/Pages/Gobierno-de-las-TIC-ISO-IEC-385001.aspx</link><description /><pubDate>Tue, 07 Feb 2012 19:13:09 GMT</pubDate></item><item><title>JOnline: Service Integration in a Multivendor Outsourced IT Environment</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-1/Pages/Service-Integration-in-a-Multivendor-Outsourced-IT-Environment1.aspx</link><description /><pubDate>Tue, 07 Feb 2012 19:14:24 GMT</pubDate></item><item><title>JOnline: Soft IT Governance</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-1/Pages/Soft-IT-Governance.aspx</link><description /><pubDate>Tue, 07 Feb 2012 19:15:03 GMT</pubDate></item><item><title>JOnline: Information Technology Compliance: Past, Present and Future</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-1/Pages/Information-Technology-Compliance-Past-Present-and-Future1.aspx</link><description /><pubDate>Tue, 07 Feb 2012 19:13:46 GMT</pubDate></item><item><title>JOnline: Using COBIT 4.1 to Achieve Business-IT Alignment: A Practical Approach</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-1/Pages/JOnline-Using-COBIT-4-1-to-Achieve-Business-IT-Alignment-A-Practical-Approach1.aspx</link><description /><pubDate>Tue, 07 Feb 2012 19:15:41 GMT</pubDate></item><item><title>JOnline: Continuous Auditing Reexamined</title><link>http://www.isaca.org/Journal/Past-Issues/2010/Volume-1/Pages/Continuous-Auditing-Reexamined1.aspx</link><description /><pubDate>Tue, 07 Feb 2012 19:12:36 GMT</pubDate></item><item><title>JOnline: Installing and Using Snort to Monitor and Control A Network</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-6/Pages/JOnline-Installing-and-Using-Snort-to-Monitor-and-Control-A-Network.aspx</link><description /><pubDate>Sun, 08 May 2011 22:20:37 GMT</pubDate></item><item><title>JOnline: Is This the Year to Automate Sarbanes-Oxley?</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-6/Pages/JOnline-Is-This-the-Year-to-Automate-Sarbanes-Oxley.aspx</link><description /><pubDate>Sun, 08 May 2011 22:22:49 GMT</pubDate></item><item><title>JOnline: Healthcare Fraud: Auditing and Detection Guide</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-6/Pages/JOnline-Book-Review-Healthcare-Fraud-Auditing-and-Detection-Guide.aspx</link><description /><pubDate>Sun, 08 May 2011 22:17:15 GMT</pubDate></item><item><title>JOnline: Seguridad Lógica y Seguridad Física: Dos Mundos Convergentes</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-6/Pages/JOnline-Seguridad-Logica-y-Seguridad-Fisica-Dos-Mundos-Convergentes.aspx</link><description /><pubDate>Sun, 08 May 2011 22:29:45 GMT</pubDate></item><item><title>JOnline: Application Security Controls: An Audit Perspective</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-6/Pages/Application-Security-Controls-An-Audit-Perspective-JOnline-1.aspx</link><description /><pubDate>Sun, 08 May 2011 22:14:55 GMT</pubDate></item><item><title>JOnline: Managing Sarbanes-Oxley Section 404 Compliance in ERP Systems Using Information Security Control Reports</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-6/Pages/JOnline-Managing-Sarbanes-Oxley-Section-404-Compliance-in-ERP-Systems-Using-Information-Security-Control-Rep1.aspx</link><description /><pubDate>Sun, 08 May 2011 22:27:48 GMT</pubDate></item><item><title>JOnline: Beyond Compliance—10 Practical Actions on Regulation, Risk and IT Management</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-5/Pages/JOnline-Book-Review-Beyond-Compliance-10-Practical-Actions-on-Regulation-Risk-and-IT-Management.aspx</link><description /><pubDate>Wed, 02 May 2012 20:39:23 GMT</pubDate></item><item><title>JOnline: Compliance Management: A Holistic Approach</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-5/Pages/JOnline-Compliance-Management-andnbsp-andnbsp-A-Holistic-Approach.aspx</link><description /><pubDate>Wed, 02 May 2012 20:40:06 GMT</pubDate></item><item><title>JOnline: Governance Best Practices for Fun and Profit</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-5/Pages/JOnline-Governance-Best-Practices-for-Fun-and-Profit.aspx</link><description /><pubDate>Wed, 02 May 2012 20:40:46 GMT</pubDate></item><item><title>JOnline: Using Information Technologies to Restore Investor Trust</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-5/Pages/JOnline-Using-Information-Technologies-to-Restore-Investor-Trust.aspx</link><description /><pubDate>Wed, 02 May 2012 20:42:10 GMT</pubDate></item><item><title>JOnline: Information Security Program: Establishing It the Right Way for Continued Success</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-5/Pages/JOnline-Information-Security-Program-Establishing-It-the-Right-Way-for-Continued-Success.aspx</link><description /><pubDate>Wed, 02 May 2012 20:41:33 GMT</pubDate></item><item><title>JOnline: Fraud or Error</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-4/Pages/JOnline-Fraud-or-Error.aspx</link><description /><pubDate>Mon, 09 May 2011 20:42:44 GMT</pubDate></item><item><title>JOnline: Mitigating IT Vulnerabilities Provides Continual Fraud Prevention</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-4/Pages/JOnline-Mitigating-IT-Vulnerabilities-Provides-Continual-Fraud-Prevention.aspx</link><description /><pubDate>Mon, 09 May 2011 20:44:52 GMT</pubDate></item><item><title>JOnline: Small Business IT Governance Implementation</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-4/Pages/JOnline-Small-Business-IT-Governance-Implementation.aspx</link><description /><pubDate>Mon, 09 May 2011 20:47:02 GMT</pubDate></item><item><title>JOnline: An Approach to Risk Assessment and Management</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-3/Pages/JOnline-An-Approach-to-Risk-Assessment-and-Management.aspx</link><description /><pubDate>Mon, 09 May 2011 22:28:47 GMT</pubDate></item><item><title>JOnline: Enterprise Architecture Metrics in the Balanced Scorecard for IT</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-3/Pages/JOnline-Enterprise-Architecture-Metrics-in-the-Balanced-Scorecard-for-IT.aspx</link><description /><pubDate>Mon, 09 May 2011 22:30:53 GMT</pubDate></item><item><title>JOnline: How to Achieve 27001 Certification: An Example of Applied Compliance Management</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-3/Pages/JOnline-How-to-Achieve-27001-Certification.aspx</link><description /><pubDate>Thu, 09 Jun 2011 22:08:55 GMT</pubDate></item><item><title>JOnline: IT Governance Implementation Using the 3P Model—A Staged Approach</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-3/Pages/JOnline-IT-Governance-Implementation-Using-the-3P-Model-A-Staged-Approach.aspx</link><description /><pubDate>Mon, 09 May 2011 22:35:43 GMT</pubDate></item><item><title>JOnline: Auditing Enterprise Resource Planning Systems </title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-2/Pages/Auditing-Enterprise-Resource-Planning-Systems-JOnline-.aspx</link><description /><pubDate>Mon, 09 May 2011 23:17:19 GMT</pubDate></item><item><title>JOnline: A Study on Canadian IT Security Practices</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-2/Pages/A-Study-on-Canadian-IT-Security-Practices-JOnline.aspx</link><description /><pubDate>Mon, 09 May 2011 23:15:27 GMT</pubDate></item><item><title>JOnline: Information Technology Legislative Update</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-2/Pages/Information-Technology-Legislative-Update-JOnline.aspx</link><description /><pubDate>Sun, 15 May 2011 21:14:44 GMT</pubDate></item><item><title>JOnline: Insider Computer Fraud: An In-depth Framework for Detecting and Defending Against Insider Attacks</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-2/Pages/Book-Review-Insider-Computer-Fraud-An-In-depth-Framework-for-Detecting-and-Defending-Against-Insider.aspx</link><description /><pubDate>Sun, 15 May 2011 21:16:23 GMT</pubDate></item><item><title>JOnline: Overcharges in the Hydrocarbon Industry</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-1/Pages/JOnline-Overcharges-in-the-Hydrocarbon-Industry.aspx</link><description /><pubDate>Tue, 11 May 2010 13:51:03 GMT</pubDate></item><item><title>JOnline: How to Write a Security Policy</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-1/Pages/JOnline-How-to-Write-a-Security-Policy.aspx</link><description /><pubDate>Tue, 11 May 2010 13:50:26 GMT</pubDate></item><item><title>JOnline: Evaluating and Selecting Sarbanes-Oxley Software</title><link>http://www.isaca.org/Journal/Past-Issues/2009/Volume-1/Pages/JOnline-Evaluating-and-Selecting-Sarbanes-Oxley-Software.aspx</link><description /><pubDate>Tue, 11 May 2010 13:48:36 GMT</pubDate></item><item><title>JOnline: Computer Ethics: A Potent Weapon for Information Security Management</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-6/Pages/JOnline-Computer-Ethics-A-Potent-Weapon-for-Information-Security-Management.aspx</link><description /><pubDate>Sun, 15 May 2011 22:07:14 GMT</pubDate></item><item><title>JOnline: Board Portals: Are They Secure?</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-6/Pages/JOnline-Board-Portals-Are-They-Secure.aspx</link><description /><pubDate>Sun, 15 May 2011 22:03:09 GMT</pubDate></item><item><title>JOnline: Cibercrimen y Ciberterrorismo: Dos Amenazas Emergentes</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-6/Pages/JOnline-Cibercrimen-y-Ciberterrorismo-Dos-Amenazas-Emergentes.aspx</link><description /><pubDate>Sun, 15 May 2011 22:05:17 GMT</pubDate></item><item><title>JOnline: Operational Risks Measurement</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-5/Pages/JOnline-Operational-Risks-Measurement1.aspx</link><description /><pubDate>Sun, 15 May 2011 22:37:41 GMT</pubDate></item><item><title>JOnline: Special Considerations for Data Warehouse Control</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-5/Pages/JOnline-Special-Considerations-for-Data-Warehouse-Control.aspx</link><description /><pubDate>Sun, 15 May 2011 22:41:30 GMT</pubDate></item><item><title>JOnline: Selecting Projects for a SAS 70 Type II Assessment</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-5/Pages/JOnline-Selecting-Projects-for-a-SAS-70-Type-II-Assessment.aspx</link><description /><pubDate>Sun, 15 May 2011 22:39:41 GMT</pubDate></item><item><title>JOnline: Evaluating Privacy Controls</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-4/Pages/JOnline-Evaluating-Privacy-Controls1.aspx</link><description /><pubDate>Wed, 18 May 2011 18:29:08 GMT</pubDate></item><item><title>JOnline: Information Systems Audit Legislation Passed in Korea</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-4/Pages/JOnline-Information-Systems-Audit-Legislation-Passed-in-Korea1.aspx</link><description /><pubDate>Wed, 18 May 2011 18:31:23 GMT</pubDate></item><item><title>JOnline: What E-commerce Audit Planners Should Remember: The Top 10 Global CSFs for B2B Audit</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-4/Pages/JOnline-What-E-commerce-Audit-Planners-Should-Remember-The-Top-10-Global-CSFs-for-B2B-Audit1.aspx</link><description /><pubDate>Wed, 18 May 2011 18:35:48 GMT</pubDate></item><item><title>JOnline: The Art of Database Monitoring</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-3/Pages/JOnline-The-Art-of-Database-Monitoring1.aspx</link><description /><pubDate>Wed, 18 May 2011 20:06:30 GMT</pubDate></item><item><title>JOnline: Billing Audit on a Mobile Operator—Call Detail Record</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-3/Pages/JOnline-Billing-Audit-on-a-Mobile-Operator-Call-Detail-Record1.aspx</link><description /><pubDate>Wed, 18 May 2011 20:02:33 GMT</pubDate></item><item><title>JOnline: Role Engineering: The Cornerstone of RBAC</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-3/Pages/JOnline-Role-Engineering-The-Cornerstone-of-RBAC1.aspx</link><description /><pubDate>Wed, 18 May 2011 20:04:26 GMT</pubDate></item><item><title>JOnline: E-business: Trust Inhibitors</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-2/Pages/JOnline-E-business-Trust-Inhibitors.aspx</link><description /><pubDate>Wed, 18 May 2011 22:23:03 GMT</pubDate></item><item><title>JOnline: Lessons From a Fraud Case in Turkey</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-2/Pages/JOnline-Lessons-From-a-Fraud-Case-in-Turkey1.aspx</link><description /><pubDate>Wed, 18 May 2011 22:24:58 GMT</pubDate></item><item><title>JOnline: SAS 70 Reports—What Do They Really Tell You?</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-2/Pages/JOnline-SAS-70-Reports-What-Do-They-Really-Tell-You1.aspx</link><description /><pubDate>Wed, 18 May 2011 22:26:59 GMT</pubDate></item><item><title>JOnline: IS Auditing Standards in Malaysia</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-1/Pages/JOnline-IS-Auditing-Standards-in-Malaysia.aspx</link><description /><pubDate>Wed, 02 May 2012 21:44:39 GMT</pubDate></item><item><title>JOnline: Data Warehouse Audits Promote and Sustain Reporting System Value</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-1/Pages/JOnline-Data-Warehouse-Audits-Promote-and-Sustain-Reporting-System-Value.aspx</link><description /><pubDate>Wed, 18 May 2011 23:11:35 GMT</pubDate></item><item><title>JOnline: Auditing IBM AS/400 and System i</title><link>http://www.isaca.org/Journal/Past-Issues/2008/Volume-1/Pages/JOnline-Auditing_IBM_AS_400_and_System_i.aspx</link><description /><pubDate>Tue, 17 Apr 2012 21:44:00 GMT</pubDate></item><item><title>JOnline: Executive and Board Roles in Information Security</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-6/Pages/JOnline-Executive-and-Board-Roles-in-Information-Security.aspx</link><description /><pubDate>Wed, 02 May 2012 21:46:39 GMT</pubDate></item><item><title>JOnline: Privacy PKI: Improved Security System for Public Administration</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-6/Pages/JOnline-Privacy-PKI-Improved-Security-System-for-Public-Administration.aspx</link><description /><pubDate>Wed, 02 May 2012 21:49:09 GMT</pubDate></item><item><title>JOnline: Monitoring Processes and Internal Control Adequacy: Continuous Monitoring Within a Microsoft Access Database</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-6/Pages/Monitoring-Processes-and-Internal-Control-Adequacy-Continuous-Monitoring-Within-a-Microsoft-Access-D1.aspx</link><description /><pubDate>Wed, 02 May 2012 21:48:30 GMT</pubDate></item><item><title>JOnline: Who Audits the IT Auditor: Monitoring IT Audit Tasks</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-5/Pages/JOnline-Who-Audits-the-IT-Auditor-Monitoring-IT-Audit-Tasks.aspx</link><description /><pubDate>Wed, 02 May 2012 21:52:34 GMT</pubDate></item><item><title>JOnline: Turning a Security Compliance Program Into a Competitive Business Advantage</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-5/Pages/JOnline-Turning-a-Security-Compliance-Program-Into-a-Competitive-Business-Advantage.aspx</link><description /><pubDate>Wed, 02 May 2012 21:51:51 GMT</pubDate></item><item><title>JOnline: One of Today's Most Overlooked Security Threats—Six Ways Auditors Can Fight It</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-5/Pages/JOnline-One-of-Todays-Most-Overlooked-Security-Threats-Six-Ways-Auditors-Can-Fight-It.aspx</link><description /><pubDate>Wed, 02 May 2012 21:51:09 GMT</pubDate></item><item><title>JOnline: Security and Privacy vs. Computer Forensics Capabilities</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-4/Pages/JOnline-Security-and-Privacy-vs-Computer-Forensics-Capabilities.aspx</link><description /><pubDate>Wed, 02 May 2012 21:56:46 GMT</pubDate></item><item><title>JOnline: Federation of E-government: A Model and Framework</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-4/Pages/JOnline-Federation-of-E-government-A-Model-and-Framework.aspx</link><description /><pubDate>Wed, 02 May 2012 21:56:10 GMT</pubDate></item><item><title>JOnline: Common Ground on Segregation of Duties in Application Management</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-4/Pages/JOnline-Common-Ground-on-Segregation-of-Duties-in-Application-Management.aspx</link><description /><pubDate>Wed, 02 May 2012 21:55:23 GMT</pubDate></item><item><title>JOnline: Certification and Accreditation: A Dilemma</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-3/Pages/JOnline-Certification-and-Accreditation-A-Dilemma.aspx</link><description /><pubDate>Wed, 02 May 2012 21:59:37 GMT</pubDate></item><item><title>JOnline: Auditing CMMI Maturity and Sarbanes-Oxley Compliance</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-3/Pages/JOnline-Auditing-CMMI-Maturity-and-Sarbanes-Oxley-Compliance.aspx</link><description /><pubDate>Wed, 02 May 2012 21:58:55 GMT</pubDate></item><item><title>JOnline: The Need for Legislation Like Sarbanes-Oxley for IT Governance: An Australian Perspective</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-3/Pages/JOnline-The-Need-for-Legislation-Like-Sarbanes-Oxley-for-IT-Governance-An-Australian-Perspective1.aspx</link><description /><pubDate>Wed, 02 May 2012 22:00:19 GMT</pubDate></item><item><title>JOnline: The Information Security Assessment and Evaluation Methodologies: A DoD Framework for Control Self-assessment</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-2/Pages/JOnline-The-Information-Security-Assessment-and-Evaluation-Methodologies-A-DoD-Framework-for-Control-Self-as1.aspx</link><description /><pubDate>Wed, 02 May 2012 22:03:15 GMT</pubDate></item><item><title>JOnline: Less Than Zero vs. Zero Day: An Approach to Vulnerabilities, Exploits, Patches and Security</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-2/Pages/JOnline-Less-Than-Zero-vs-Zero-Day-An-Approach-to-Vulnerabilities-Exploits-Patches-and-Security.aspx</link><description /><pubDate>Wed, 02 May 2012 22:02:37 GMT</pubDate></item><item><title>JOnline: Using Systems Engineering to Aid in HIPAA Compliancy</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-2/Pages/JOnline-Using-Systems-Engineering-to-Aid-in-HIPAA-Compliancy.aspx</link><description /><pubDate>Wed, 02 May 2012 22:03:58 GMT</pubDate></item><item><title>JOnline: Change Management in Process Change</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-1/Pages/JOnline-Change-Management-in-Process-Change.aspx</link><description /><pubDate>Wed, 02 May 2012 22:23:12 GMT</pubDate></item><item><title>JOnline: Clause 49: An Opportunity for Indian-listed Corporations to Achieve IT Governance</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-1/Pages/JOnline-Clause-49-An-Opportunity-for-Indian-listed-Corporations-to-Achieve-IT-Governance.aspx</link><description /><pubDate>Wed, 02 May 2012 22:24:00 GMT</pubDate></item><item><title>JOnline: Controlling Spreadsheets</title><link>http://www.isaca.org/Journal/Past-Issues/2007/Volume-1/Pages/JOnline-Controlling-Spreadsheets.aspx</link><description /><pubDate>Wed, 02 May 2012 22:24:45 GMT</pubDate></item><item><title>JOnline: Telephone Line Scanning Still Matters</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-6/Pages/JOnline-Telephone-Line-Scanning-Still-Matters1.aspx</link><description /><pubDate>Wed, 02 May 2012 22:28:18 GMT</pubDate></item><item><title>JOnline: A Framework for Conducting IT Due Diligence in Mergers and Acquisitions</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-6/Pages/JOnline-A-Framework-for-Conducting-IT-Due-Diligence-in-Mergers-and-Acquisitions1.aspx</link><description /><pubDate>Wed, 02 May 2012 22:26:59 GMT</pubDate></item><item><title>JOnline: Framework for Measuring and Reporting Performance of Information Security Programs in Offshore Outsourcing</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-6/Pages/JOnline-Framework-for-Measuring-and-Reporting-Performance-of-Information-Security-Programs-in-Offshore-Outso1.aspx</link><description /><pubDate>Wed, 02 May 2012 22:27:41 GMT</pubDate></item><item><title>JOnline: Implementing COBIT in Higher Education: Practices That Work Best</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-5/Pages/JOnline-Implementing-COBIT-in-Higher-Education-Practices-That-Work-Best1.aspx</link><description /><pubDate>Wed, 02 May 2012 22:30:36 GMT</pubDate></item><item><title>JOnline: Understanding Data Classification Based on Business and Security Requirements</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-5/Pages/JOnline-Understanding-Data-Classification-Based-on-Business-and-Security-Requirements1.aspx</link><description /><pubDate>Wed, 02 May 2012 22:31:57 GMT</pubDate></item><item><title>JOnline: Sarbanes-Oxley Act Compliance: Strategies for Implementing an Audit Committee Complaints Procedure</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-5/Pages/JOnline-Sarbanes-Oxley-Act-Compliance-Strategies-for-Implementing-an-Audit-Committee-Complaints-Procedure1.aspx</link><description /><pubDate>Wed, 02 May 2012 22:31:14 GMT</pubDate></item><item><title>JOnline: Beyond Checklists: A Socratic Approach to Building a Sustainable Change Auditing Practice</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-4/Pages/JOnline-Beyond-Checklists-A-Socratic-Approach-to-Building-a-Sustainable-Change-Auditing-Practice1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:19:43 GMT</pubDate></item><item><title>JOnline: The Need for and Implementation of Audit Trails</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-4/Pages/JOnline-The-Need-for-and-Implementation-of-Audit-Trails1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:21:52 GMT</pubDate></item><item><title>JOnline: Technology Platform or Application—Which Will Best Fulfill Compliance Needs?</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-4/Pages/JOnline-Technology-Platform-or-Application-Which-Will-Best-Fulfill-Compliance-Needs1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:20:48 GMT</pubDate></item><item><title>JOnline: Virtualization Usage, Risks and Audit Tools</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-3/Pages/JOnline-Virtualization-Usage-Risks-and-Audit-Tools1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:26:32 GMT</pubDate></item><item><title>JOnline: Information Assurance—Online Lottery Systems</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-3/Pages/JOnline-Information-Assurance-Online-Lottery-Systems1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:25:35 GMT</pubDate></item><item><title>JOnline: Concept Mapping—A Learning Tool for the Information Systems Audit Profession</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-3/Pages/JOnline-Concept-Mapping-A-Learning-Tool-for-the-Information-Systems-Audit-Profession1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:24:31 GMT</pubDate></item><item><title>JOnline: Delegating Root Authority and Auditing Activities on UNIX/Linux Systems</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-2/Pages/JOnline-Delegating-Root-Authority-and-Auditing1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:32:52 GMT</pubDate></item><item><title>JOnline: Road Map for Information Security: What to Do After BS 7799 Certification</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-2/Pages/JOnline-Road-Map-for-Information-Security-What-to-Do-After-BS-7799-Certification1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:34:14 GMT</pubDate></item><item><title>JOnline: Strengthening Access Control: Using Smart Cards</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-2/Pages/JOnline-Strengthening-Access-Control-Using-Smart-Cards1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:36:08 GMT</pubDate></item><item><title>JOnline: Network Intrusion Detection: Know What You Do (Not) Need</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-1/Pages/JOnline-Network-Intrusion-Detection-Know-What-You-Do-Not-Need.aspx</link><description /><pubDate>Mon, 07 May 2012 19:40:00 GMT</pubDate></item><item><title>JOnline: ID Theft: Fraudster Techniques for Personal Data Collection, the Related Digital Evidence and Investigation Issues</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-1/Pages/JOnline-ID-Theft-Fraudster-Techniques-for-Personal-Data-Collection-the-Related-Digital-Evidence-and-Investi1.aspx</link><description /><pubDate>Mon, 07 May 2012 19:38:41 GMT</pubDate></item><item><title>JOnline: The SAP Landscape That Warrants Audit</title><link>http://www.isaca.org/Journal/Past-Issues/2006/Volume-1/Pages/JOnline-The-SAP-Landscape-That-Warrants-Audit.aspx</link><description /><pubDate>Mon, 07 May 2012 19:40:49 GMT</pubDate></item><item><title>JOnline: On a Mission to Merge</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-6/Pages/JOnline-On-a-Mission-to-Merge1.aspx</link><description /><pubDate>Mon, 07 May 2012 20:01:05 GMT</pubDate></item><item><title>JOnline: Trazabilidad de las Operaciones Electrónicas. Un Reto para la Gerencia de Tecnologías de Información</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-6/Pages/JOnline-Trazabilidad-de-las-Operaciones-Electronicas-Un-Reto-para-la-Gerencia-de-Tecnologias-de-Informacion1.aspx</link><description /><pubDate>Mon, 07 May 2012 20:02:33 GMT</pubDate></item><item><title>JOnline: Creating and Enforcing an Effective Information Security Policy</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-6/Pages/JOnline-Creating-and-Enforcing-an-Effective-Information-Security-Policy1.aspx</link><description /><pubDate>Mon, 07 May 2012 20:00:05 GMT</pubDate></item><item><title>JOnline: An Approach to Vulnerability Management</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-5/Pages/JOnline-An-Approach-to-Vulnerability-Management1.aspx</link><description /><pubDate>Mon, 07 May 2012 20:20:37 GMT</pubDate></item><item><title>JOnline: Security Information Management: Not Just the Next Big Thing</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-5/Pages/JOnline-Security-Information-Management-Not-Just-the-Next-Big-Thing1.aspx</link><description /><pubDate>Mon, 07 May 2012 20:21:35 GMT</pubDate></item><item><title>JOnline: ERP Postimplementation Problems</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-4/Pages/JOnline-ERP-Postimplementation-Problems.aspx</link><description /><pubDate>Mon, 07 May 2012 21:33:43 GMT</pubDate></item><item><title>JOnline: How Does Information Security Fit Into a Governance Framework?</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-4/Pages/JOnline-How-Does-Information-Security-Fit-Into-a-Governance-Framework.aspx</link><description /><pubDate>Mon, 07 May 2012 21:34:22 GMT</pubDate></item><item><title>JOnline: How the New Standards and Regulations Affect an Auditor's Assessment of Compliance With Internal Controls</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-4/Pages/JOnline-How-the-New-Standards-and-Regulations-Affect-an-Auditors-Assessment-of-Compliance-With-Internal-Cont1.aspx</link><description /><pubDate>Mon, 07 May 2012 21:35:17 GMT</pubDate></item><item><title>JOnline: The 10 Most Important Things an IT Person Must Understand About Security Across the Enterprise</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-3/Pages/JOnline-The-10-Most-Important-Things-an-IT-Person-Must-Understand-About-Security-Across-the-Enterprise1.aspx</link><description /><pubDate>Mon, 07 May 2012 21:51:04 GMT</pubDate></item><item><title>JOnline: Information Security and the Human Factor</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-3/Pages/JOnline-Information-Security-and-the-Human-Factor1.aspx</link><description /><pubDate>Mon, 07 May 2012 21:49:41 GMT</pubDate></item><item><title>JOnline: The Development of a Shared CIO/Executive Management Understanding and Its Impact on Information Systems Strategic Alignment</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-3/Pages/JOnline-The-Development-of-a-Shared-CIO-Executive-Management-Understanding-and-Its-Impact-on-Information-Sys1.aspx</link><description /><pubDate>Mon, 07 May 2012 21:51:38 GMT</pubDate></item><item><title>JOnline: IT Governance—Practical Case Using COBIT</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-3/Pages/JOnline-IT-Governance-Practical-Case-Using-COBIT1.aspx</link><description /><pubDate>Mon, 07 May 2012 21:50:25 GMT</pubDate></item><item><title>JOnline: Generic Exploit Blocking: Prevention, Not Cure</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-2/Pages/JOnline-Generic-Exploit-Blocking-Prevention-Not-Cure.aspx</link><description /><pubDate>Mon, 07 May 2012 22:03:24 GMT</pubDate></item><item><title>JOnline: IT Governance: Pass or Fail?</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-2/Pages/JOnline-IT-Governance-Pass-or-Fail.aspx</link><description /><pubDate>Mon, 07 May 2012 22:04:04 GMT</pubDate></item><item><title>JOnline: Potential Control Processes for Sarbanes-Oxley Compliance</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-2/Pages/JOnline-Potential-Control-Processes-for-Sarbanes-Oxley-Compliance.aspx</link><description /><pubDate>Mon, 07 May 2012 22:04:44 GMT</pubDate></item><item><title>JOnline: Enterprise Instant Messaging: Taking Control</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-1/Pages/JOnline-Enterprise-Instant-Messaging-Taking-Control.aspx</link><description /><pubDate>Mon, 07 May 2012 22:16:28 GMT</pubDate></item><item><title>JOnline: Fingerprint Identification: An Aid to the Authentication Process</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-1/Pages/JOnline-Fingerprint-Identification-An-Aid-to-the-Authentication-Process.aspx</link><description /><pubDate>Mon, 07 May 2012 22:17:09 GMT</pubDate></item><item><title>JOnline: A Network Is Threatened by Its Own Endpoints</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-1/Pages/JOnline-A-Network-Is-Threatened-by-Its-Own-Endpoints.aspx</link><description /><pubDate>Mon, 07 May 2012 22:15:45 GMT</pubDate></item><item><title>JOnline: Strategies and Influence for Information Security</title><link>http://www.isaca.org/Journal/Past-Issues/2005/Volume-1/Pages/JOnline-Strategies-and-Influence-for-Information-Security.aspx</link><description /><pubDate>Mon, 07 May 2012 22:17:54 GMT</pubDate></item></channel></rss>