L’IT Governance Institute (ITGI) , espressione dell'ISACA, ha reso disponibile la pubblicazione "COBIT Security Baseline (seconda edizione)". Il documento, che riporta il sottotitolo "an information security survival kit" scaricabile per gli associati ISACA (pdf, 420 K , 50 pp), affronta in modo completo la problematica di sicurezza IT dal punto di vista della compliance e della governance. Comprende il mapping fra COBIT 4.1 e ISO/IEC 17799:2005 ed il censimento dei “Security Risk” più importanti
Indice
- Introduction
- COBIT as a Foundation for Good Security Practices
- Security Is Not a One-time Effort
- Document Structure
- Information Security Defined
- Current Risks—Why Information Security Is Important
- COBIT Security Baseline - 44 Steps Towards Security
- Information Security Survival Kit 1 - Home Users
- Specific Information Security Risks for Home Users
- Home Users Survival Kit
- Information Security Survival Kit 2 - Professional Users
- Specific Information Security Risks for Professional Users
- Professional Users Dos and Don’ts
- Information Security Survival Kit 3—Managers
- Specific Information Security Risks for Managers
- Managers Checklist
- Information Security Survival Kit 4—Executives
- Specific Information Security Risks for Executives
- Executives Questions and Actions
- Information Security Survival Kit 5—Senior Executives
- Specific Information Security Risks for Senior Executives
- Senior Executives Questions and Actions
- Information Security Survival Kit 6—Boards of Directors/Trustees
- Specific Information Security Risks for Board Members
- Directors and Trustees Questions and Actions
- Summary of Technical Security Risks
- Intentional Misuse of the Computer
- Violation of Rules and Regulations
- Accidents
- References
- General Information Security and IT Governance Standards and Frameworks
- General Information Security Web Sites
- Technical Information Security Guidance
- Information Security News
- Appendix— COBIT and Related Products
Articoli collegati in questo sito
Link
- ISACA (sito USA)
- L’ IT Governance Institute (ITGI)
- IsacaRoma, capitolo ISACA di Roma
- AIEA, capitolo ISACA di Milano