Blogs about: Security Program Development

Featured Blog

More on Staffing and Governance

jtbevis wrote 1 month ago: I been tracking via this blog a good amount of search hits looking for security staffing and governa … more →

Tags: Security Staffing, Security Governance

Security Survey Polls Added

jtbevis wrote 3 months ago: The polls are open! While visiting this site please check out the new IS Management page and contrib … more →

Tags: Security Staffing, Security Governance

Authoritative List of Compliance Documents

jtbevis wrote 5 months ago: For anyone looking to find or understand the main key compliance documents across the following indu … more →

Tags: Policy and Compliance, Risk Assessment, Security Governance

Working Toward ISO 17799/27001 Business Continuity Management Compliance1 comment

jtbevis wrote 5 months ago: This document is written with the assumption that the organization follows ISO and has implemented m … more →

Tags: business continuity, Policy and Compliance

IT Security Spending 10% of IT Operating Budget1 comment

jtbevis wrote 9 months ago: 10% of IT budget seems high.  It would be nice if someone provided an industry breakdown.  I can … more →

Tags: Security Governance

The Top Ten Convention Information Security Measures

jtbevis wrote 10 months ago: The Ten Most Important Things That The CSO Of The Republican and Democratic Conventions Should Be Do … more →

Tags: Security Awareness, Security Governance

Risk Based Security Plan - Whitepaper

jtbevis wrote 1 year ago: This whitepaper has a good overview of key components of a risk based security plan, which have been … more →

Tags: Risk Assessment, Security Governance, Security Staffing

Information Security Staffing – Skills Identification and Training Budget

jtbevis wrote 1 year ago: One of the key problems a security manger must tackle is defining the budget for security training.  … more →

Tags: Security Staffing, Security Governance, Security Awareness

Disaster Recovery – Alternate Site Geographical Distance1 comment

jtbevis wrote 1 year ago: There is an article that came out earlier from DRJ (Thomas L. Weems) based on a study that provides … more →

Tags: Risk Assessment, Security Governance, business continuity, Security Awareness

New Foundstone Blog1 comment

jtbevis wrote 1 year ago: Its about time!  Foundstone Professional Services has been added to the Avert Labs research blog.  S … more →

Tags: Passwords, Patches, Risk Assessment, Security 2.0, Security Awareness, Security Governance, Security Staffing, Social Engineering, Threats

Security Spending - How Much of IT Budget2 comments

jtbevis wrote 1 year ago: There is an article on The Register web site claiming security spending has soared to 20% of the IT … more →

Tags: Security Staffing, Security Governance, Security Awareness

Extreme Social Engineering Paper1 comment

jtbevis wrote 1 year ago: The PhishMe blog on building employee awareness to social engineering tactics was inspiring so I fin … more →

Tags: Risk Assessment, Security Governance, Social Engineering, Security Awareness

BS 31100 Code of Practice for Risk Management2 comments

jtbevis wrote 1 year ago: The BS 31100 Code of practice for risk management is also out in draft form free to download and rev … more →

Tags: Risk Assessment, Policy and Compliance

BS 25999-2 Business Continuity Management

jtbevis wrote 1 year ago: The BS 25999-2 Specification for business continuity management is out in draft form free to downloa … more →

Tags: Policy and Compliance, business continuity

MTA NYC Explosion: Poor Business Continuity

jtbevis wrote 1 year ago: It’s amazing that after so many disasters and crisis in NYC that the MTA (Metropolitan Transportatio … more →

Tags: What doesn't work, Security Governance, business continuity

Good HIPAA - RISK Assessment Topics2 comments

jtbevis wrote 2 years ago: I came across a pretty good list of topics that Auditors ask for in a HIPAA audit.  This is usually … more →

Tags: Risk Assessment

Roles & Responsibilities in Policy6 comments

jtbevis wrote 2 years ago: Risk Assessments almost always produce one finding consistently.  The finding is lack of roles and r … more →

Tags: Policy and Compliance, Risk Assessment, Security Governance, Security Staffing

Writing Effective Policies Part I 1 comment

jtbevis wrote 2 years ago: How do you write an effective policy that actually works?  A coworker and I recently published a whi … more →

Tags: Policy and Compliance, Risk Assessment, Security Governance

Upcoming Privacy and Security Panel in Las Vegas2 comments

jtbevis wrote 2 years ago: For those who are interested I will be sitting on a panel in Las Vegas on May 22nd.  The topic is … more →

Tags: Risk Assessment, Security Governance, Privacy


Have your say. Start a blog.

See our free features →

Related Tags
All →

Follow this tag via RSS

Find other items tagged with “security-program-development”:
Technorati Del.icio.us IceRocket