IT Job Descriptions

Security Manual Template

Salary Survey

Disaster Plan

IT Infrastructure Strategy Charter



XML and RSS News Feeds
CIO Tools - Disaster Planning - Security
Infrastructure - Job Descriptions



Business continuity planning becomes more critical

03/04/2010 

The more your business relies on its IT systems, the more you need to consider how unexpected disruptions might affect your business. These disruptions could come in many forms, from fire and floods to theft or malicious attacks on your systems, such as viruses or hacking.

Business continuity planning improves your business' ability to react to such disruptions. It describes how you will restart your operations in order to meet your business-critical requirements.

Order DRP BCP Download DRP BCP

The business continuity template can be used for any sized enterprise. The Disaster Recovery template and supporting material have been updated to be ISO 27000, Sarbanes-Oxley, PCI-DSS, and HIPAA compliant. The Template explains the importance of business continuity plans to the success of your business, and how best to develop them.

- more info




Goverment to add new mandates on Internet companies

03/03/2010 Senator Richard Durbin, the assistant majority leader, is planning legislation that will require US Internet companies to uphold human rights abroad.  "With a few notable exceptions, the tech industry seems unwilling to regulate itself,” Durbin said. “I will introduce legislation that will require Internet companies to take reasonable steps to protect human rights, or face civil and criminal liability."
- more info




Compliance concers of CIOs

02/24/2010 

Major security legislation that CIOs should be concernted wtih are based on where they operate and who their customers are.

Enterprises doing business within the United States

  • SOX – The Sarbanes-Oxley Act of 2002 requires strict internal controls and independent auditing of financial information as a proactive defense against fraud.
  • HIPAA – The Health Information Portability and Accountability Act of 1996 requires tight controls over handling of and access to medical information to protect patient privacy.
  • GLBA – The Gramm-Leach-Bliley Act of 1999 requires financial institutions to create, document and continuously audit security procedures to protect the nonpublic personal information of their clients, including precautions to prevent unauthorized electronic access.

Enterprises doing business with the US Federal Government

  • FISMA – The Federal Information Security Management Act of 2002 is meant to bolster computer and network security within the federal government and affiliated parties (such as government contractors) by mandating yearly audits.

Enterprises doing business internationally

  • Basel II – The Capital Requirements Directive/Basel II Accord established an international standard that banking regulators can use when creating regulations about how much capital banks need to put aside to guard against the types of financial and operational risks banks face.
  • UK Data Protection Act of 1998 – The eight principles of the Data Protection Act state that all data must be processed fairly and lawfully; obtained and used only for specified and lawful purposes; adequate, relevant and not excessive; accurate, and where necessary, kept up to date; kept for no longer than necessary; processed in accordance with individuals rights as defined in the Act; kept secure; and transferred only to countries that offer adequate data protection.
- more info




Security demands CIOs to adapt as new threats appear

02/20/2010 

Security ManualIt is not easy to keep an enterprise successful and secure these days. Businesses all over the world are faced with a host of new challenges: an unsteady economy, growing competition, volatile global markets, shrinking budgets, and consumer uncertainty. Overworked IT departments are not only expected to respond to the demands of anxious business teams, they’re also responsible for securing the organization and its valuable data against a raft of sophisticated new threats they have never seen before; proving their processes are internally and externally compliant; and being fiscally responsible.

The security policies and procedures template by Janco is the perfect solution.  It helps CIOs and IT Managers create the proper security environment.

Because of the way security has evolved over the years, it is rarely looked upon or "fulfilled the role" as a strategic business enabler. Some see it as an inescapable and often costly necessity. The approach to security is generally driven by the latest threats; it is reactive rather than proactive, tactical rather than strategic.

- more info




64 bit processors take off

02/16/2010 

Good news for fans of technological progress: Windows 7 is on track to become the first Microsoft desktop OS that's as popular in its 64-bit (x64) format as it is in the legacy 32-bit (x86) format that has dominated PCs for nearly two decades. The Infrastructure is changing.

A recent survey by the folks behind the Steam online gaming network shows that, at least among gaming enthusiasts, 64-bit is now the more popular way to go, with the majority of gamers running the x64 variants of Vista or Windows 7.

According to records drawn from its 23,000-strong user base, more than half of Windows 7 PCs are running the 64-bit version. This is remarkable in that the exo.performance.network user base consists primarily of enterprise IT users, not hardcore gamers like Steam's users. Moreover, it represents a significant uptick in 64-bit use versus that in Windows 7's immediate predecessor, Windows Vista. Of the thousands of Vista machines monitored by the network, less than one in five are running the x64 edition.

- more info




Security Risks and Compliance Requirement Defined

02/09/2010 

For businesses today, managing IT security risk and meeting compliance requirements is paramount. The past decade has seen an unprecedented wave of security breaches that have compromised the integrity of company-owned information -  resulting in substantial financial and operational loss while devastating the confidence of customers, business partners and stakeholders. This tide of events has led to the establishment of technical standards, IT governance frameworks and laws designed to improve and enforce security - creating further pressure for organizations to define, control and govern their IT infrastructure more effectively.

Numerous laws and regulatory mandates focus on corporate governance and accountability around sensitive information (specifically financial, non-public information and protected healthcare information). This has significantly impacted the underlying IT systems that support the applications and repositories holding this sensitive information. Organizations are continuously looking for help in preventing fraud and protecting sensitive information. The fact that key corporate executives carry personal liability in the event of non-compliance virtually ensures compliance to be a key initiative in any large organizations. Additionally, there are other internal cost-containment requirements that can be effectively met by defining and implementing a sound auditing and compliance methodology. Most corporations agree that compliance leads to better corporate governance and management.

- more info




Goverments sites hacked -- again

01/31/2010 

Someone defaced the Web pages of nearly 50 members of the U.S. House of Representatives with an explicit insult to President Obama after he gave his State of the Union address on Wednesday night.

The 49 House Web sites, representing both Democrats and Republicans, were managed by a company called GovTrends, The Associated Press reported on Thursday.

Security Manual Template

ISO 27000 / HIPAA / SOX / CobiT Compliant
Includes PCI DSS Audit Program
Table of ContentsOrder

The hacking occurred while GovTrends was performing an update, Jeff Ventura, spokesman for the House chief administrative officer, told the AP.

Last August, 18 House sites managed by GovTrends were also defaced, according to Ventura, who added that the House is reconsidering the business relationship with the Web site service provider.

- more info




How secure is your sensitive data?

01/27/2010 

Security ManualThe prevailing model of enterprise network security is rooted in the axiom that being "physically inside is safe and outside is unsafe." Connecting to a network point within the enterprise is generally considered safe and is subject to weaker security controls. On the other hand, tight security controls are enforced at the network traffic entry and exit points using firewalls and VPNs. A WLAN breaks the barrier provided by the building perimeter as the physical security envelope for a wired network because invisible radio signals used by the WLAN cannot be confined within the physical perimeter of a building, and usually cut through walls and windows. Firewalls, VPN and 802.11i become ineffective at protecting the network from hackers, but there are certain security measures you can take.

Buy nowTable of Contents

This Security Manual for the Internet and Information Technology is over 240  pages in length and is ISO 27000 Compliant. All versions of the Security Manual template include both the Business & IT Impact Questionnaire and the Threat & Vulnerability Assessment Tool (both were redesigned to address Sarbanes Oxley compliance).  

- more info




Outsourcing issues CIOs need to address

01/19/2010 

Outsource OutsourcingCIOs need to avoid issues associated with their businesses as they operate in a crisis mode. Outsourcing decisions will be made in haste and be too simplistic and sudden to deliver real business advantage.

  • CIO should start their sourcing endeavor by building a solid sourcing strategy that focuses on creating short and long term value. This strategy should be aligned with the organization's sourcing management maturity and include business value scenarios, open options and a road map of value creation with a timeline of expected results.
  • CIOs must take a long-term view of the developing global presence of countries that can provide high-quality resources at the right price point. If your geographic presence is diverse, seek providers that are not exclusively focused on single country, so that you can mitigate risks (such as geopolitical instability) and also take advantage of the benefits of alternative countries, which may offer opportunities close to your own growth markets.
  • CIOs should actively monitor the market to determine the best combination of software and IT services and service provider options to meet their requirements and specify their appetite for risk.
- more info




Security a key issue

01/13/2010 

Security Policies and Procedures and Audit Program

Some industries inherently deal with extremely sensitive data – financial services, healthcare and law firms are among some of the businesses that cannot risk a data breach due to an employee emailing a file that could be compromised en route. It is imperative that their knowledge workers and staff had a bullet-proof way to move files.

- more info