What CEO’s need to be concerned about

Security Internet / External Shortage of key skills Industry consolidation Changes in type/level of competition Impact of the Internet Downward pressure prices Environment, health, and safety issues Change in supply/distribution systems Access to / cost of capital Changing technology Regulatory issues (labor, market access, etc) Effect of corruption Currency issues Stakeholder relations Pressure from institutional… Continue reading What CEO’s need to be concerned about

Liability of Internetwork Carriers

The Internet is undergoing a rapid transition.  Two key, interrelated trends are easily discerned.  First, commercial traffic is now being carried on and across many networks.  Second, many networks are being operated more like businesses than research experiments.  New entities have been created as profit-seeking enterprises.   In this environment, internet-work carriers strongly feel the need… Continue reading Liability of Internetwork Carriers

Identity Management Glossary of Terms

Acquisition device: The hardware used to acquire biometric samples. Acquisition device: The hardware/sensors used to acquire biometric samples. These would include finger sensors or readers, iris scanning devices, facial recognition cameras. Automated Fingerprint Identification System (AFIS): A system that compares a single fingerprint with a database of fingerprint images. Automated Fingerprint Identification System (AFIS): Automated… Continue reading Identity Management Glossary of Terms

SLA / OLA Service Considerations for Building Computing Operating Environments

Describe the environment in which the system will be used and define the major availability, reliability, performance, and integrity requirements. This information will significantly influence the definition of the systems architecture. Consider questions such as: Are the users widely distributed geographically or located close to each other? How many time zones are they in? When… Continue reading SLA / OLA Service Considerations for Building Computing Operating Environments

Net Time Servers

Time Servers                              time.nrc.ca       ntp0.fau.de       time.nist.gov       time-a.nist.gov       time-b.nist.gov       time-c.timefreq.bldrdoc.gov       time-b.timefreq.bldrdoc.gov       time-a.timefreq.bldrdoc.gov       nist1.datum.com Windows command to set / synchronize your time:                  net time /setsntp:time.nrc.ca

Sample Visio, Word, PowerPoint and MindMap – Compliance files

Best IT Document Solutions are far more detailed and comprehensive these samples offer a condensed version of the quality of solutions we offer. Technical_Writing_Style.doc All of these MindMap files Customer Relationship Management.mmap Finance & Administration.mmap Human Resources.mmap Industry Specific.mmap Integrated Services Management.mmap Procurement.mmap HL PCI Domains.mmap Free Sample Document downloads – Compliance research documents: Compliance_ppt1.zip… Continue reading Sample Visio, Word, PowerPoint and MindMap – Compliance files

Identity (IdM) Warehouse described

Support for hierarchical organizational units-organizational structure, reporting structure or functional units Application Metadata Definition Simplified user and entitlements import process – Import from csv, xml, txt and other format files – Import directly from some ldap & odbc sources – Import from Identity Management Systems – Import using RBAC ETL processing • Flexible User Entitlements Correlation Engine • Import… Continue reading Identity (IdM) Warehouse described

Core XML Standards

Introduction to XML The eXtensible Markup Language (XML) is a specification introduced by the World Wide Web Consortium (W3C) for identifying and organizing elements of information in electronic documents. XML is the result of scaling down the Standard Generalised Markup Language or SGML for short an earlier standard for document representation, developed and standardised by… Continue reading Core XML Standards

Rational Unified Process (RUP)

Rational Unified Process (RUP) RUP is a development concept developed by Rational to support development teams with a set of guidelines to successfully implement system applications. Its core principles can be summarised in the following six issues: Iterative development to lessen the risks already in the early phases of the project Effective management of requirements… Continue reading Rational Unified Process (RUP)

Zachman Framework

Architecture Frameworks Zachman Framework is the first and probably most influencing architecture framework. Two key ideas are illustrated in the Zachman Framework: 1. There is a set of architectural representations produced over the process of building a complex engineering product representing the different perspectives of the different participants. 2. The same product can be described, for different… Continue reading Zachman Framework

Role Based Access Market Needs

Determine – ‘Who has access to what’ – ‘If people have the right access for their job’ • Demonstrate compliance to auditors – RBAC Model – Recertification of Entitlements • Efficient User Access Process – Assign access based on ‘business roles’ – Simplified process for creating and managing roles • Clean up orphaned accounts, legacy system accounts and access outside… Continue reading Role Based Access Market Needs

PCI Carholder Information Security Program

Carholder Information Security Program. European Payment Council (EPC). Securing Visa Cardholder Data When customers offer their bankcard at the point of sale, over the Internet, on the phone, or through the mail, they want assurance that their account information is safe. That’s why Visa USA has instituted the Cardholder Information Security Program (CISP). Mandated since… Continue reading PCI Carholder Information Security Program

Identity Compliance Described

Supports enterprise level monitoring of access for segregation of duty (SoD) and security policy conflicts Ability to define rules across any platform / database / application or user’s attributes Support for inter and intra application security policy enforcement Monitoring of SoD, role vs actual exceptions, and terminated users with active accounts exceptions Comprehensive list of… Continue reading Identity Compliance Described

What is an Application Audit

What is an Application Audit Usually required to assess • Business risk• Internal control• Strong linkage to corporate governance and compliances such as SOX, PCI, HIPAA and GLBA It is an audit of a single application • Example: audit of an Excel spreadsheet with embedded macros It could also be an audit of business processes that use… Continue reading What is an Application Audit

Simple Shutdown script for an Exchange Server

@echo off net stop MSExchangeES net stop IMAP4Svc net stop POP3Svc net stop RESvc net stop MSExchangeSRS net stop MSExchangeMGMT net stop MSExchangeMTA net stop MSExchangeIS /Y net stop MSExchangeSA /Y ! ! net stop “Computer Browser”” net stop “Messenger” net stop “Net Logon” net stop “NT LM Security Support Provider” net stop “Plug and… Continue reading Simple Shutdown script for an Exchange Server

Services deleted or modified in Windows 2000 that were in Windows NT 4

Services deleted or modified in Windows 2000 that were in Windows NT 4 Process Manager creates and deletes processes and also tracks process objects and thread objects. Local Procedure Call Facility using a client/server relationship provides a communications mechanism between the applications and the Environmental subsystem. Services added or modified in Windows 2000 that were… Continue reading Services deleted or modified in Windows 2000 that were in Windows NT 4

Digital Rights Management Key Subjects

Management of the DRM Function Data Resource Management Sample Charter / Mission Statement Goals, Objectives and Critical Success Factors Benefits of Data Resource Management Enterprise-wide Data Management Process Maturity Data Resource Management Job Descriptions Data Resource Activities The Framework for Enterprise Architecture Information Stewardship Accountability for Information Quality Repository Management Building the Meta Data Repository… Continue reading Digital Rights Management Key Subjects

Common Referenced Related Laws, Regulations, and Policies

The following Federal laws, directives, regulations provide guidance pertaining to the security automated information systems: Privacy Act of 1974 (Public Law [PL] 93-579, United States Code [U.S.C.] 552A) Freedom of Information Act (5 U.S.C.522) Paperwork Reduction Act of 1986 (44 U.S.C. 35) Electronic Communications Privacy Act of 1986 (PL 99-508) Computer Fraud and Abuse Act… Continue reading Common Referenced Related Laws, Regulations, and Policies

Information Technology Requirements

The objectives of this activity are to: o Identify and document functional requirements related to potential systems, o Identify and document data requirements related to potential systems, o Identify and document technical requirements related to potential systems, o Identify and document integration requirements related to potential systems, o Identify and document communications requirements related to potential systems, o Prioritize the… Continue reading Information Technology Requirements

Sample Information Security Project Plan

Sample Information Security Project Plan Planning & Organization Define a Strategic IT Plan Define the Information Architecture Determine the Technological Direction Define the IT Organization and Relationships Manage the IT Investment Communicate Management Aims and Direction Manage Human Resources Ensure Compliance with External Requirements Assess Risks Manage Projects Manage Quality   Acquisition & Implementation Identify… Continue reading Sample Information Security Project Plan

Cellular / Mobile Standards History

Cellular / Mobile Standards History 0G MTS (1946 – US, Bell System) IMTS (1969 – US, Bell System) OLT (1966 – Norway) AMTS (Japan) ARP (1971 – Finland) MTD (1971 – Sweden) 1G 1G cell phone technology encompassed analog standards introduced in the 1980s and continued until replaced by 2G digital cell phones. NMT (1981-… Continue reading Cellular / Mobile Standards History

UNIX sed Commands

Unix sed Commands  sed ‘s/wizard/guru/g’ file1                   replaces every occurrence of the string wizard with the string guru sed -n ‘s/wizard/guru/gp’ file1              replaces and prints only those lines where the substitution was                                                              made  -n print only when command p is given sed ‘/Comment:/d’ file1                          deletes all the lines that contain Comment: from the file. sed… Continue reading UNIX sed Commands