This site contains the tools that the Chief Information Officer - CIO , Chief Technology Officer -CTO, Chief Security Officer - CSO, and Chief Financial Officer -CFO can use for Sarbanes Oxley, Disaster Recovery, Security, Job Descriptions, IT Service Management, Change Control, Help Desk, Service Requests, SLAs - Service Level Agreements, and Metrics.
Recent Blogs
- Data Breach and Network Intrusion Protection Bundle a Great tool By Site Administrator| 05/26/2008
- Are High Paying IT Jobs Being Off-Shored? By Site Administrator| 05/13/2008
- Things CIOs and CTOs need to do to succeed By Site Administrator| 04/14/2008
- Sure ways to scuttle your career By Site Administrator| 03/24/2008
- What will the impact of StartKey and USB drives be? By Site Administrator| 03/3/2008
- Has Microsoft lost its way? By Site Administrator| 03/2/2008
- Vista SP1 Has Mixed Reviews 0x80070020 Errors Unresolved By Site Administrator| 02/21/2008
- The recession started in September 2007 By Site Administrator| 02/5/2008
- Are Blades the right solutions By Site Administrator| 01/30/2008
- The stock market downturn will impact IT By Site Administrator| 01/23/2008
Recent News
Microsoft Tool Windows Advisor to be Released Soon
- Published 05/28/2008
Windows Advisor is an easy-to-use self-help tool that notifies users about problems on their PCs and helps fix them. Windows Advisor scans users PCs continuously, notifies them about important issues, and, when possible, suggests easy fix solutions. The program also provides users with self-help solutions, including a 1-click checkup function that enables them to check their PCs whenever they like; tips and tutorials that teach users how to perform certain actions on their PCs; and a toolbox that concentrates the important tools that are found in the operating system into one easy-to-find location » Read More
Data Breach and Network Intrusion Protection Bundle Released by Janco
- Published 05/24/2008
Data breaches are a fact of life with the advance of Wi-Fi, 3G, and remote computing as it is done in todays flexible business environment.
Data breaches and network intrusions occur because the personal
information compromised includes data elements useful to identity thieves, such
as Social Security numbers, account numbers, and driver's license numbers. Some
breaches do not expose such sensitive information; however, they still expose
individuals to identity theft and business to a compromise of their electronic
assets and that must be disclosed under Sarbanes-Oxley and various state
laws.
Janco has defined a set of tools which enterprises of all sizes can use to be prepared to protect against breaches and intrusion, know when it occurs, and provides the ability to respond quickly when it does happen.
» Read MoreSQL Injection Attack in China Impacts Disaster Recovery
- Published 05/23/2008
In an IDG story it was disclosed that web sites across China and Taiwan are being hit by a mass SQL injection attack that has implanted malware in thousands of Web sites, according to a security company in Taiwan.
The attack in China and Taiwan is ongoing. In addition with the impact of the earthquake and the associated relief efforts, the attack is having a huge impact. Even if they cannot successfully insert malware, they are killing lots of Web sites right now, because they are just brute-forcing every attack surface with SQL injection, and hence causing lots of permanent changes to the victim Web sites.
In a SQL injection attack, an attacker attempts to exploit vulnerabilities in custom Web applications by entering SQL code in an entry field, such as a log-in. If successful, such an attack can give the attacker access to data on the database used by the application and the ability to run malicious code on the Web site.
Mass SQL injection attacks have increasingly become a security threat. In January, tens of thousands of PCs were infected by an automated SQL injection attack. That attack exploited a vulnerability in Microsoft Corp.'s SQL Server.
Thousands of Web sites have been hit by the attack, he said, noting that 10,000 servers alone were infected by malware on Friday. Most of the affected servers are in China, while some are located in Taiwan. The attackers appear to be using automated queries to the Google search engine to identify Web sites vulnerable to the attack, he said.
The attackers in the more recent outbreak are not targeting a specific vulnerability. Instead, they are using an automated SQL injection attack engine that is tailored to attack Web sites using SQL Server. The attack uses SQL injection to infect targeted Web sites with malware, which in turn exploits vulnerabilities in the browsers of those who visit the Web sites.
The malware injected by the attack comes from 1,000 different servers and targets 10 vulnerabilities in Internet Explorer and related plug-ins that are popular in Asia.
» Read MoreRecord Retention Is Mandated for Most Organizations
- Published 05/14/2008
Virtually all organizations must satisfy statutory
records retention requirements, including broad-based requirements such as the
Americans with Disabilities Act, the Age
Discrimination in Employment Act and the Occupational Safety and
Health Act. For example, the Sarbanes-Oxley Act impacts all public companies and
has been a prime point for regulatory compliance. A few of the many mandated
requirements are:
-
SEC 17a
-
FINRA 3010
-
FDIC Advisory
-
Investment Advisors Act of 1940 (hedge funds)
-
Gramm-Leach-Bliley Act
-
IDA 29.7
-
FDA 21 CFR Part 11
-
OCC Advisory
-
HIPAA
-
Financial Modernization Act 1999
-
Medicare Conditions of Participation
-
Fair Labor Standards Act
-
Americans with Disabilities Act
-
Toxic Substances Control Act
-
UK Data Protection Act
-
UK Companies Act
-
UK Company Law Reform Bill - Electronic Communications
-
UK Combined Code on Corporate Governance 2003
-
UK Human Rights Act
-
UK Anti-Terrorism, Crime and Security Act 2001
-
Basel II
-
Markets in Financial Instruments Directive
Although many records retention requirements do not impose specific requirements on email or instant messages, Janco has found that approximately 80% of enterprises use email for closing orders or performing other types of business transactions. As a result, email is housing a greater proportion of corporate and other records and so increasingly is subject to statutory records retention requirements.
» Read MoreMatrix to Map Business Needs with IT Requirements Defined by Janco
- Published 05/13/2008
|
Business Requirement |
IT Requirement |
|
Quick
Time-to-Market |
Ability to roll our new applications and technology is expanded with the use of System-Oriented Architecture (SOA) |
|
Restructuring business
due to merger, acquisition, or divestiture |
Ability to add, change and eliminate IT operations thru an effective design and implementation of a structured IT Infrastructure for both networks and data centers |
|
Integration of IT
technology with business operations |
Ability to implement and operate on a 7 by 24 basis for all applications, application support, network, and processing operations. this includes having integrated Business Continuity and Disaster Reovery Plans implemented |
|
Compliance with
mandated security and financial reporting
requirements |
Defined policies, procedures, and processes which quickly and efficiently support business operations without hindering to overall effectiveness of the processes that are put in place to support them |
|
Maintain an ROI which
is supports the long-term objectives of the
business |
Metrics that are tied to the Critical Success Factors (CSFs) the enterprise and are supported by defined Service Level Agreements (SLAs) |
Featured Articles
What do you need to do if you are laid off
- By Site Administrator
- Published 02/5/2008
- Career
- Unrated
Network failure is a critical Disaster Plan issue
- By Site Administrator
- Published 11/29/2007
- Internet , Disaster Recovery Planning , Business Management , Information Technology
-
Rating:




Network operation is a critical component of any Disaster Recovery and Business Continuity Plan. Historical data shows that failures are caused by serveral factors.
Disaster Planning, Business Continuity, and Security Template and Audit Program Bundle
- By Site Administrator
- Published 11/20/2007
- Promotional Offers , Disaster Recovery Planning , Information Technology
-
Rating:




As the year end approaches, now is the best time to get ready for you external auditors. You want to be prepared for their focus on security and compliance with all of the mandated requirements. Get a comprehensive set of thoroughly researched and tested and concise audit programs (and templates) which you and your staff can proactively implement.
Service Level Agreements & Metrics - How to Implement IT Service Management
- By Site Administrator
- Published 11/15/2007
- Promotional Offers , Information Technology
-
Rating:




Start Improving IT Service and Cutting Your Technology Costs Today Technology is always one of the areas where management looks to cut costs during budget season, and IT Cost Control - Metrics - SLA - ITSM kits provide savvy guidance to help you reduce expenses while maintaining your effectiveness.
SIM Targets Shrinking IT Workforce in U.S.
- By Site Administrator
- Published 11/12/2007
- Education , Career , Business , Information Technology
-
Rating:




With a national IT labor shortage likely to emerge over the next decade, the Society for Information Management is extending its IT career programs to high school students. Several demographic studies indicate that labor shortages are possible. For example, AMR Research Inc. found that 76 million Americans will reach retirement age during the next 10 years. And SIM predicts that enrollment in college IT courses is dropping by 40% annually. Meanwhile, the U.S. Department of Commerce Office of Technology estimates that about 2.5 million IT jobs will have been created in the U.S. between 2000 and 2010. The AEA estimates that the number of IT workers stood at 5.6 million at the end of 2005. To help address the anticipated IT labor shortfall, SIM plans this year to expand its college IT career programs to high school students. The organization intends to reach out to high school students and guidance counselors by drawing upon a program created by its Dallas chapter, said Leo Collins, SIMs vice president of advocacy and communities of interest.
ISO 27000 iis not compliant to the list of all SOX requirements
- By Site Administrator
- Published 11/12/2007
- Business Management , Information Technology
- Unrated
ISO 27000 is not fully compliant to the list of all SOX requirements, as SOX was conceived in the USA and targeted especially if not only for USA-based companies and not mandatory for European ones, while ISO standards are thought as international standards to be applied by all corporations from all countries.
Question arises which standards should you comply with and will it be enough?
IT Service Management is key to Success
- By Kent Foster
- Published 11/11/2007
- Information Technology
- Unrated
IT Service Management is not for the faint of heart. Support professionals, help desk staff, and even network administrators, already consumed with a barrage of break-fix requests, must also manage a constant stream of challenging user administration tasks. Add to the mix the responsibility for deploying or upgrading new user accounts, software, and equipment, and you have the conditions for every harried IT professionals perfect storm.
Standardizing your organizations approach to creating, maintaining, and removing end user accounts and managing assets is an excellent method of streamlining such responsibilities. Best of all, the time you save administering accounts and tracking equipment can be dedicated to addressing migrations, upgrades, outages, failures, and other crises. But where should you start?
Fortunately, much of the work has already been completed. Janco Associates IT Service Management Template for a Service Oriented Architecture defines what small and medium businesses and even large enterprises require to efficiently manage day-to-day IT Service Management tasks.
The template includes:
-
Service Requests Policy
-
Service Request Standard
-
Help Desk Policy
-
Help Desk Procedures
-
Help Desk Service Level Agreement
-
Change Control Standard
-
Change Control Quality Assurance Standard
-
Change Control Management Workbook
-
Documentation Standard
-
Application Version Control Standard
-
Version Control Standard
-
Internet Policy
-
e-Mail Policy
-
Electronic Communication Policy
-
Blog & Personal Web Site Policy
-
Travel and Off-Site Meeting
-
Sensitive Information Policy
Productivity With Productivity Metrics
- By Site Administrator
- Published 11/25/2007
- Internet , Business Management , Information Technology
-
Rating:




Defining a Business Plan
- By Site Administrator
- Published 11/25/2007
- Business Management , Information Technology
-
Rating:




A business plan is a plan that you may show any finance providers when your trying to get finance to either help set your business up and or to help you get out of a hole when your business is struggling for cash flow A definition of a business plan is a written document that includes many aspects of your business including financial aspects, marketing, time appreciation and your short and long term goals for your business.
Recent Articles
Web-Content Conundrum
- By Jerry Bader
- Published 04/30/2008
- Internet
- Unrated
The Future Of Spam
- By Kim Falkner
- Published 04/17/2008
- Internet
- Unrated
Ordering An ADSL Line
- By Derek Rogers
- Published 04/16/2008
- Internet
- Unrated
You're Guide To ADSL Broadband?
- By Derek Rogers
- Published 04/16/2008
- Internet
- Unrated
Business Taking Care Of Business
- By Lorraine Hansen
- Published 04/14/2008
- Business
- Unrated
ADSL Lines - Explained
- By Derek Rogers
- Published 04/14/2008
- Information Technology
- Unrated
Working Of Cell Phones
- By Roberto Sedycias
- Published 04/13/2008
- Information Technology
- Unrated
Digital Generation Gap - Back To The Basics
- By Allison Merlino
- Published 04/13/2008
- Information Technology
- Unrated
Computer Features - Choosing The Best System For Your Needs
- By Allison Merlino
- Published 04/13/2008
- Information Technology
- Unrated
Keeping Score With Marketing ROI
- By Sam Miller
- Published 04/8/2008
- Business Management
- Unrated
IT & Business Infrastructure








