Appendix B: Must Read's™ “Security and Risk Management”
The list of readings for security was superseded by the products of ISACA under Harmonization and Standards alignment. In my own defense, the list below existed before I read the CISM and harmonization efforts. I was simply relieved to discover my “must-reads” were on target from the perspectives as published by IIA, AICPA and ISACA.
|
Title (s) |
Used to |
Copyright Cost |
Supporting Frameworks and Standards |
|
NIST Special Publication 800-30, Risk Management Guide for Information Technology Systems, As implemented with 53, 53a, and FIPS 199. 200, 201 |
In conjunction with NIST Special Publication 800-53, Recommended Security Controls for Federal Information Systems
|
Gary Stoneburner, from NIST and Alice Goguen and Alexis Feringa, |
Written to comply with OMB Circular A-130-- Management of Federal Information Resources and Public Law 104-13 a.k.a. Paperwork Reduction Act of 1995[165]. |
|
BS ISO/IEC 27001:2005 (BS 7799-2:2005) |
Copyright BSI; cost is listed in Swiss franks Uses previous contributions made by
|
Intended for use in Federal and internationally regulated industry, used for Conformity Assessment
|
|
|
Corporate Information Security Working Group: Report of the Best Practices and Metrics Teams |
Public Domain also ISG Tool. |
Intended for any United States Public or Private Security Organization
|
|
|
Governing for Enterprise Security Networked Systems Survivability Program |
Public Domain |
Intended for any United States Public or Private Security Organization, Julia Allen, 2005 |
|
|
OCTAVE Information Security Risk Evaluation |
Produced by Defense Advanced Research Projects Agency (DARPA) contributions by Christopher Alberts Audree Dorofee James Stevens Carol Woody |
Intended for any United States Public or Private Security Organization |
|
|
COBIT:COBIT®: Security Baseline: An Information Security Survival Kit COBIT: Security Baseline: An Information Security Survival Kit COBIT:COBIT®: Security Baseline: An Information Security Survival Kit
|
Public Domain (requires login as ISACA member, but the login cost is supported as “required” by anyone in IT systems audit.) |
Intended for any United States Public or Private Security Organization
|
|
|
FFIEC Information Technology Examination Handbook
|
Federal Regulated Federal Reserve Board (FRB), Federal Deposit Insurance Corporation (FDIC), National Credit Union Administration (NCUA), Office of the Comptroller of the Currency (OCC), and Office of Thrift Supervision (OTS) |
Public Domain
|
|
|
Global Technology Audit Guide (GTAG) Information Technology Controls (Change and Patch Management)
|
|
|
|
|
Enterprise Risk Management--Integrated Framework
|
|
COSO (must be purchased) |
|
|
ISO/IEC 15408 International Standard; Common Criteria for Information Technology Security Evaluations CEM: Evaluation Methodology cem V3.0.pdf
|
CC Part 1: Introduction and general model ccpart1 V3.0.pdf CC Part 2: Security functional components ccpart2 V3.0.pdf CC Part 3: Security assurance components ccpart3 V3.0.pdf |
|
|
Bibliography
This bibliography includes references whose source is not previously cited within the document text. Also included are references to influential people and other documents related to the subject area.
Berinato, Scott, Darwin Magazine, http://www.darwinmag.com/read/0502/apples.html.
BSI, British Standards Institute, "BS ISO/IEC 17799:2005", in British Standard ISO/IEC 27001:2005, London, United Kingdom: The Stationary Office, 2005.
Clark, James Bryce (
Deming, Edwards (1986), "14 Points for Management", in Out of Crisis, 1986, Cambridge: The MIT Press, http://www.deming.org/resources/books.html.
EDUCAUSE & Internet2, Computer and Network Security Task Force, EDUCAUSE/Internet2 Computer and Network Security Task Force.
Governance Assessment Tool for Higher Education, http://www.educause.edu/ir/library/pdf/SEC0421.pdf.
FASP, Federal Agency Security Practices, "STIGs, Security Technical Implementation Guides", http://csrc.nist.gov/pcig/cig.html.
FERF, Financial Executives Research Foundation, http://www.fei.org/rf/.
FIPS, Federal Information Processing Standards Publication, http://www.itl.nist.gov/fipspubs/.
Frye, Emily, “Cybersecurity and Corporate Governance Now: Does It Take Liability to Get Attention?”, in American Bar Association, Section Of Science & Technology Law, Chicago 2005, http://www.documation.com/aba/pdfs/004.pdf.
GAAP, Generally Accepted Accounting Principles, http://www.fasab.gov/accepted.html.
GAP, Government Accountability Project, http://www.whistleblower.org/template/index.cfm.
Gibaldi, Joseph (2003), MLA Handbook for Writers of Research Papers, 6th Edition, http://www.mla.org/handbook.
Gruber, Tom, What is an Ontology?, KSL, Knowledge Systems, AI Laboratory, Stanford University, http://www-ksl.stanford.edu/kst/what-is-an-ontology.html.
McNamara, Robert S. and Morris, Errol, The Fog of War: Eleven Lessons from the Life of Robert S. McNamara, December 2003.
NHGRI, National Human Genome Research Institute, http://www.genome.gov/.
NSSN, National Standards Systems Network, "STAR, Standards Tracking and Automated Reporting, Services", http://www.nssn.org/star_intro.html.
OntoWeb Project, OntoWeb Working Group on Process Standards, http://www.aiai.ed.ac.uk/project/ontoweb/. Amy Knutilla, Craig Schlenoff, Steven Ray, Stephen T. Polyak, Austin Tate, Shu Chiun Cheah and Richard C. Anderson: "Process Specification Language: An Analysis of Existing Representations," NISTIR 6160, National Institute of Standards and Technology, Gaithersburg, MD, 1998.
PricewaterhouseCoopers on behalf of COSO, COSO, Enterprise Risk Management — Integrated Framework, AICPA, Volume 2, https://www.cpa2biz.com/CS2000/Products/CPA2BIZ/Publications/COSO+Enterprise+Risk+Management+-+Integrated+Framework.htm, & COSO (2005), Internal Control — Integrated Framework, Guidance for Smaller Public Companies Reporting on Internal Control over Financial Reporting, AICPA, Exposure Draft, http://155.201.80.182/Coso/coserm.nsf/vwResources/PDF_IC/$FILE/COSO_FINAL_Draft_IC_Guidance.pdf.
PricewaterhouseCoopers, Integrity Driven Performance - White Paper, © Copyright 2004 PricewaterhouseCoopers, Page 34.
Ross, Dr. Ron and NIST, Protecting Federal Information Systems and Networks, A Standards-based Security Certification Program for Operational Environments, http://cio.doe.gov/Conferences/Security/Presentations/RossRNIST.pps.
Skadden Biography, Michael S. Hines, http://www.skadden.com/index.cfm?contentID=45&bioID=2732.
Smith, Lawrence W., "The FASB’s Efforts Toward Simplification", in The FASB Report, February 28, 2005, http://www.fasb.org/articles&reports/fasb_efforts_toward_simplification_tfr_feb_2005.pdf.
Spafford Jr., George, Spafford Global Consulting, Inc., Saint Joseph, MI, http://www.spaffordconsulting.com.
Swanson, Dan and Seccuris Inc., Security Benchmark, http://www.securitybenchmark.com.
TQM, Total Quality Management, http://www.managementhelp.org/quality/tqm/tqm.htm.
U.S. Department of Labor, Bureau of Labor Statistics, Occupational Employment and Wages, November 2004, http://www.bls.gov/oes/current/oes132011.htm.
U.S. Navy, Benefits, "Increasing Contractor Commitment", http://www.ar.navy.mil/aosfiles/tools/turbo/topics/cj.cfm.
United States Congress & Subcommittee on Technology, Information Policy, Intergovernmental Relations and the Census (2004). Oversight Hearing Statement by Adam Putnam, Chairman, Identity Theft: The Causes, Costs, Consequences, and Potential Solutions. http://www.reform.house.gov/UploadedFiles/Final%20Press%20Opening%20Statement%202.pdf, p. 5.
United States Congress, "DMCA", "Digital Millennium Copyright Act", in Public Law 105-304, H.R. 2281, S. 2037, & Congressional Record Vol. 144 (1998), Washington: U.S. Government Printing Office, 112 Stat. 2860 & 2905.
VISA International Service Association, Security Programs, http://corporate.visa.com/st/programs.jsp.
Walsh, Norman and Muellner, Leonard, DocBook: The Definitive Guide, O'Reilly & Associates, Inc, Version 1.0.2 (1999), http://www.oreilly.com/catalog/docbook/chapter/book/docbook.html.
Endnotes
[1] United States Congress, Sarbanes-Oxley Act of 2002, 15 U.S.C. §7201 (2002), "Sarbanes-Oxley Act of 2002", "SOX", in Public Law 107-204, H.R. 3763, S. 2673, & Congressional Record Vol. 148 (2002), Washington: U.S. Government Printing Office, 116 STAT. 745-810.
[2] COBIT®. Retrieved December 1, 2005 http://www.isaca.org/Template.cfm?Section=CobiT6&Template=/TaggedPage/TaggedPageDisplay.cfm&TPLID=55&ContentID=7981.
[3] COSO, Committee of Sponsoring Organizations of the Treadway Commission. Retrieved December 1, 2005 http://www.coso.org/.
[4] ITIL®, Information Technology Infrastructure Library. Retrieved December 1, 2005 http://www.ogc.gov.uk/index.asp?id=2261.
[5] BSI, British Standards Institute, "BS ISO/IEC 17799:2005", in British Standard ISO/IEC 27001:2005, London, United Kingdom: The Stationary Office, 2005.
[6] ISACA, Information Systems Audit and Control Association. Retrieved December 1, 2005 http://www.isaca.org/.
[7] OGC, Office of Government Commerce, "ICT Infrastructure Management", in ITIL® Series, London, United Kingdom: The Stationary Office, 2002.
[8] Edgar Allen Poe, Tell-Tale Heart, USA: BookSurge Classics, Philadelphia: J. B. Lippincott Co., 1895.
[9] George Lucas, Star Wars, Episode IV, A New Hope, USA Box Office: Lucas Films Ltd., 1977.
[10] Andy Wachowski & Larry Wachowski, The Matrix, USA Box Office: Groucho II Film Partnership, Silver Pictures, & Village Roadshow Pictures, 1999. Note: Scene with Lawrence Fishburn training Keanu Reeves in martial arts.
[11] NIST, National Institute of Standards and Technology. FIPS, Federal Information Processing Standards Publication. Retrieved December 1, 2005 from http://www.itl.nist.gov/fipspubs/.
[12] United States Congress, "FISMA", "Federal Information Security Management Act of 2002", in Public Law 107-347, H. R. 2458-48, Title III, Washington: U.S. Government Printing Office, SEC 301-305.
[13] U.S. Department of Homeland Security. FEMA, Federal Emergency Management Agency. Retrieved December 1, 2005 from http://www.fema.gov/.
[14] GAO Accounting and Information Division. FISCAM, Federal Information System Controls Audit Manual Volume I: Financial Statement Audits, Washington: Government Accountability Office, 1999. Retrieved December 1, 2005 from http://www.gao.gov/special.pubs/ai12.19.6.pdf.
[15] George Orwell, Animal Farm, New York: New American Library, 1956. Note: Orwell's book title did not inspire "Compliance Farm™". Any similarity is coincidental and unintentional. I assure you I only read the Cliff Notes®.
[16] Robin Basham, “Fish", "Sheep", "Snake", "Dog", "Wolf", "Eagle”, in Compliance Farm™, 2005. Note: Inspired by and with thanks to A.J. Jacobs, Fractured Fairy tales (1997) & Warner Brother’, Looney Tunes (1961), amended by various mental pop ups, most recently 2005.
[17] K-NET. Retrieved December 1, 2005 http://www.isaca.org/knet. Note: K-NET is provided by ISACA as a professional resource and describes it as "a global knowledge network for IT Governance, Control and Assurance" and “K-NET contains over 5,200 peer-reviewed web site resources pertaining to knowledge covering IT Governance, Assurance, Security and Control. Full access to K-NET is reserved for association members. In addition, a personalized tracking feature […]. Reference items are organized into logical categories of interest and concern".
[18] Dan Swanson & Michael Legary (2005). Security Benchmark. Retrieved December 1, 2005 from http://www.securitybenchmark.com. Note: Dan Swanson and Michael Legary's list of Information Security Organizations is recently listed among the top 5 security resources worldwide.
[19] CERT/CC, Computer Emergency Readiness Team/Coordination Center. Retrieved December 1, 2005 http://www.cert.org/. Note: CERT Coordination Center resources are coordinated by Carnegie Mellon University and the Software Engineering Institute.
[20] IIA, The Institute of Internal Auditors. Retrieved December 1, 2005 http://www.theiia.org.
[21] ISACA, ISACA Downloads. Retrieved December 1, 2005 from http://www.isaca.org. Note: Most downloads require ISACA membership.
[22] ITGI & OGC (2005). Aligning COBIT®, ITIL® and ISO 17799 for Business Benefit. Retrieved December 1, 2005 from http://www.isaca.org/.
[23] ISO, International Organization for Standards. Retrieved December 1, 2005 http://www.iso.org.
[24] IEC, International Electrotechnical Commission. Retrieved December 1, 2005 http://www.iec.ch/.
[25] COBIT®, COBIT®: Project. Retrieved December 1, 2005 from http://www.isaca.org/Content/NavigationMenu/Members_and_Leaders/CobiT6/Project1/CobiT_Project.htm. Note: COBIT® has recently released Edition 4.0.
[26] ITGI, IT Governance Institute. Retrieved December 1, 2005 http://www.itgi.org. Note: ITGI describes itself as "The IT Governance Institute (ITGI) exists to assist enterprise leaders in their responsibility to ensure that IT is aligned with the business and delivers value, its performance is measured, its resources properly allocated and its risks mitigated." and "[ITGI] is a not-for-profit research organization affiliated with the Information Systems Audit and Control Association® (ISACA®), a global not-for-profit professional membership organization focused on IT Governance, assurance and security, with more than 47,000 members in more than 140 countries. ITGI undertakes research and publishes COBIT®, an open standard and framework of controls and best practice for IT governance."
[27] OGC, Office of Government Commerce. Retrieved December 1, 2005 http://www.ogc.gov.uk. Note: As explained by the OGC as "[…] a UK government organization responsible for procurement and efficiency improvements in the UK public sector. OGC has produced world-class best practice guidance, including PRINCE (project management), MSP (Managing Successful Programs) and ITIL® (IT service management). ITIL® is used throughout the world and is aligned with the ISO/IEC 20000 international standard in service management."
[28] Everett C. Johnson, ITGI's International President, Named one of the top 100 most influential accountants in America, he additionally served on the American Institute of Certified Public Accountants (AICPA) Assurance Services Executive Committee and currently chairs the AICPA Privacy Task Force. He has served as chairman for the International Federation of Accountants (IFAC) Information Technology Committee and the AICPA Information Technology Research Subcommittee. Johnson has more than 40 years of experience in IS audit, control and security. He most recently was a partner at Deloitte & Touche, where he served as the Latin American regional director of the company’s enterprise risk services line and the US national and global leader for the computer assurance services practice.
[29] Staff Liaison: Thomas Lamm, Director of Research, Standards, and Academic Relations (
[30] GAAP, Generally Accepted Accounting Principles. Retrieved December 1, 2005 http://www.fasab.gov/accepted.html.
[31] David Richards, President of IIA is described in public forum by IIA Chairman Bob McDonald, CIA, CGAP, as a leader who can build consensus on difficult issues such as globalization and strategic planning.
[32] The Institute of Internal Auditors. GTAG, Global Technology Audit Guide. Retrieved December 1, 2005 from http://www.theiia.org/index.cfm?doc_id=4706.
[33] GTAG, ibid., Guide 1: Information Technology Controls. Retrieved December 1, 2005 from http://www.theiia.org/index.cfm?doc_id=5166.
[34] John Wiley & Sons, Inc. Cliff Notes, CliffNotes®. Retrieved December 1, 2005 from http://www.cliffsnotes.com/WileyCDA/Section/id-106262.html. Note: CliffNote, without a space, is the registered trade mark for the study aids which are commonly referred to as Cliff Notes, with a space.
[35] AICPA, American Institute of Certified Public Accountants. Retrieved December 1, 2005 http://www.aicpa.org/index.htm.
[36] CIS, Center for Internet Security. Retrieved December 1, 2005 http://www.cisecurity.org/. Note: CIS provides Benchmarks and Scoring Tools, free of charge.
[37] CMU/SEI, Carnegie Mellon University/Software Engineering Institute. Retrieved December 1, 2005 http://www.sei.cmu.edu/.
[38] ISSA, Information Systems Security Association. Retrieved December 1, 2005 http://www.issa.org/.
[39] NASD, National Association of Corporate Directors. Retrieved December 1, 2005 http://www.nacdonline.org/.
[40] SANS Institute, SysAdmin Audit Network Security Institute. December 1, 2005 http://www.sans.org/aboutsans.php.
[41] COBIT®, COBIT® Online. Retrieved December 1, 2005 from http://www.isaca.org.
[42] Note: Town zoning committee warned me. The additional 63 meters of paper puts Mount Must Read™ in a new category of land mass. I continue to argue the definition of hill vs. mountain based in geological definition; “Hill: A natural land elevation, usually less than 1000 feet above its surroundings, with a rounded outline. The distinction between hill and mountain depends on the locality.” My view is, if its base is in my office I can call it a hill.
[43] TQM, Total Quality Management. Retrieved December 1, 2005 http://www.managementhelp.org/quality/tqm/tqm.htm.
[44] United States Congress, "HIPA", "Health Insurance Portability and Accountability Act of 1996", in Public Law 104-191, H.R. 3103, S. 1028, S. 1698, & Congressional Record Vol. 142 (1996), 110 STAT. 1936-2103.
[45] United States Congress, "GLBA", "Gramm–Leach–Bliley Act", in Public Law 106-102, H.R. 10, S. 900, & Congressional Record Vol. 145 (1999), Washington: U.S. Government Printing Office, 113 STAT. 1340-1481.
[46] GAP, Government Accountability Project. Retrieved December 1, 2005 http://www.whistleblower.org/template/index.cfm.
[47] United States Congress, "SOX", in Public Law 107-204, loc.cit.
[48] United States Congress, "GLBA", in Public Law 106-102, loc.cit.
[49] United States Congress, "HIPAA", in Public Law 104-191, loc.cit.
[50] United States Congress, "Securities Exchange Act of 1934", in 15 U.S.C. § 78, Title I - Regulation of Securities Exchanges, 1934, SEC 1-36.
[51] United States Congress, "FOIA", "Freedom of Information Act", in P.L. 104-231, FOIA Update Vol. XVII, No. 4, 1996, 110 STAT. 3048.
[52] NIST, National Institute of Standards and Technology. Retrieved December 1, 2005 http://www.nist.gov/. Note: “The National Institute of Standards and Technology (NIST) developed this document in furtherance of its statutory responsibilities under the Federal Information Security Management Act (FISMA) of 2002, Public Law 107-347.
NIST is responsible for developing standards and guidelines, including minimum requirements, for providing adequate information security for all agency operations and assets; but such standards and guidelines shall not apply to national security systems. This guideline is consistent with the requirements of the Office of Management and Budget (OMB) Circular A-130, Section 8b(3), .Securing Agency Information Systems,. as analyzed in A-130, Appendix IV: Analysis of Key Sections. Supplemental information is provided in A-130, Appendix III. “
[53] European Parliament & The Council Of The European Union, "EUDPD", "EU Data Protection Directive", in Directive 95/46/EC, No L. 281 (1995), Luxembourg, Official Journal of the European Communities, p. 31. & Senate and House of Commons of Canada, Department of Justice Canada, "PIPEDA", "Personal Information Protection and Electronic Documents Act", in Bill C-54, 2000, c. 5, Note: EUDPD and PIPEDA will absolutely have impact in the way most publicly owner and operated company’s conduct their business. I simply narrowed these two items and the laws of WTO so I could create a consumable list.
[54] ECS, Education Commission of the States (2002). Citizenship Education Inclusion in Assessment and Accountability Systems. Retrieved December 1, 2005 from http://mb2.ecs.org/reports/Report.aspx?id=107.
[55] United States House of Representatives, Parliamentarian, Mr. Ney, & Charles W. Johnson. How Our Laws Are Made. Retrieved December 1, 2005 from http://thomas.loc.gov/home/lawsmade.toc.html.
[56] College of Liberal Arts. Think Tanks & Research Institutes. Retrieved December 1, 2005 from http://www.libarts.ucok.edu/political/links/think.htm.
[57] SIL International. Think Tanks. Retrieved December 1, 2005 from http://www.sil.org/sildc/ThinkTanks_DC.htm.
[58] United States Think Tank List. Earth's Common Sense Think Tank. Retrieved December 1, 2005 from http://www.venusproject.com/ecs/world_news/think_tank_list.html.
[59] National Council for Science and the Environment. Congressional Research Service Reports. Retrieved December 1, 2005 from http://www.ncseonline.org/NLE/CRS/.
[60] NHGRI, National Human Genome Research Institute. Retrieved December 1, 2005 http://www.genome.gov/. Note: NHGRI provides legal glossary including: “Codification “, defined as “laws or regulations that are codified are general and permanent laws or regulations that are arranged in subject-matter order by title or other major subdivision and section (as opposed to session laws, which are generally presented in chronological order). The text of the original law or regulation is collated with any subsequent amendments (additions to or deletions from the language of the original law or regulation), so as to provide the most up-to-date text of the law or regulation. Most bills or session laws indicate (either in either the text or the margin) the title (or other major subdivision) and section number of the U.S. Code or the state code in which the law will appear.”
[61] United States Congress, "Circular 92", "Copyright Law of the United States of America and Related Laws Contained in Title 17 of the United States Code", in United States Code, Title 17 (1976), Washington, U.S. Government Printing Office, Chapters 1-8 & 10-12.
[62] GPO, Government Printing Office. Retrieved December 1, 2005 http://www.gpoaccess.gov/index.html.
[63] United States Congress. "DMCA", "Digital Millennium Copyright Act", in Public Law 105-304, H.R. 2281, S. 2037, & Congressional Record Vol. 144 (1998), Washington: U.S. Government Printing Office, 112 Stat. 2860 & 2905. Note: Review of the DMCA reveals in contribution the name of Mike S. Hines, who is frequently in discussion on various ISACA and CMU sanctioned list services. Mike contributes to the Information Security Management group, under ISACA sponsor, mailto:info-sec-manager@orbit.sparklist.com. Recommendation, send email with the word “join” in subject and no other text to
[64] United States Congress. "Computer Fraud and Abuse Act", in 18 U.S.C. § 1030, 1986. Retrieved December 1, 2005 from http://cio.doe.gov/Documents/CFA.HTM.
[65] U.S. House of Representatives. Download United States Code. Retrieved December 1, 2005 from http://uscode.house.gov/download/download.shtml.
[66] The Library of Congress. Thomas. Retrieved December 1, 2005 from http://thomas.loc.gov/.
[67] ISACAF, Information Systems Audit and Control Foundation (2002). Electronic and Digital Signatures - A Global Status Report. Retrieved December 1, 2005 from http://www.isaca.org/Content/ContentGroups/Bookstore6/Intros_and_Summaries/Electronic_and_Digital_Signatures__A_Global_Status_Report____Executive_Introduction.htm. Note: ISACA membership may be required to review this report.
[68] FFIEC, Federal Financial Institutions Examination Council. Retrieved November 1, 2005 http://www.ffiec.gov/.
[69] NIST, loc.cit.
[70] AICPA, loc.cit.
[71] COSO, loc.cit.
[72] NARA, National Archives and Records Administration. Retrieved December 1, 2005 http://www.archives.gov/.
[73] GAO, Government Accountability Office. Retrieved December 1, 2005 http://www.gao.gov/.
[74] George Spafford Jr. President, Spafford Global Consulting, Inc. Note: George Spafford Jr. provides substantial direction in current information affecting IT audit and information systems law. Spafford Global Consulting, Inc., 3353 Celina Avenue, Saint Joseph, MI 49085 USA.
[75] Dan Swanson, Security Benchmark. Note: Dan Swanson’s SEC daily email has over 6000 reading members. He provides summaries and reminders regarding our profession’s most substantial contributions, and includes many pointers to public companies and products supporting audit and legal requirements. To become members of these mailing email
[76] James Bryce Clark, (
[77] Participation in a TC, such as the OASIS DCML/ Configuration and Standards, will expose any participant to more brilliant thinkers and areas of technology previously thought possible. http://www.oasis-open.org/who/. Participation with the ISACA community offers witness to world leadership. The lists are available for IT and Audit professionals interested in Governance, COBIT®, Legal Issues in Audit, and IT Audit in general. The following links to join are all you need.
[78] Office of Management and Budget. "Circular No. A-130 Revised", in Transmittal Memorandum No. 4, Memorandum For Heads Of Executive Departments And Agencies. Retrieved December 1, 2005 from http://www.whitehouse.gov/omb/circulars/a130/a130trans4.html.
[79] Office of Management and Budget. "Circular No. A-119 Revised, Accompanying Federal Register Materials", in Federal Participation in the Development and Use of Voluntary Consensus Standards and in Conformity Assessment Activities. Retrieved December 1, 2005 from http://www.whitehouse.gov/omb/circulars/a119/a119.html.
[80] United States Congress, "Cyber Security Research and Development Act", in Public Law 107-305, H.R. 3394, S. 2182, & Congressional Record Vol. 148 (2002), Washington: U.S. Government Printing Office, 116 STAT. 2367-2382. Retrieved December 1, 2005 from http://thomas.loc.gov/cgi-bin/bdquery/z?d107:H.R.3394:@@@L&summ2=m&. Note: Summary of impacts resulting from this law, as amended 10/16/2002, include reference to NIST including:“[…]Requires the NIST Director to develop CNS checklists for Federal Government computer hardware or software systems. (Sec. 9) Amends NISTA to authorize appropriations to enable the Computer System Security and Privacy Advisory Board to: (1) identify emerging issues related to computer security, privacy, and cryptography; (2) convene public meetings, and (3) publish and disseminate information. (Sec. 10) Requires NIST to carry out specified types of intramural computer security research. (Sec. 11) Authorizes appropriations to the Secretary of Commerce for NIST for: (1) the CNS research program; and (2) intramural computer security research. (Sec. 12) Requires the NIST Director to arrange with the National Research Council of the National Academy of Sciences to study and report to specified congressional committees on vulnerabilities of the Nation's network infrastructure and recommendations for improvements.(Sec. 13) Requires the NSF and NIST Directors to: (1) coordinate the research programs under this Act; and (2) work with the Director of the Office of Science and Technology Policy to ensure that programs under this Act are taken into account in any Government-wide cyber security research effort. […].
[81] NIST, op.cit.
[82] FASP, Federal Agency Security Practices. STIGs, Security Technical Implementation Guides. Retrieved December 1, 2005 from http://csrc.nist.gov/pcig/cig.html.
[83] CIS, Center for Internet Security. CIS Benchmarks/Scoring Tools. Retrieved December 1, 2005 from http://www.cisecurity.org/bench.html.
[84] NIAC, National Infrastructure Advisory Council (February 2003). The National Strategy to Secure Cyberspace, Washington: Department of Homeland Security. Retrieved December 1, 2005 from http://www.dhs.gov/interweb/assetlibrary/National_Cyberspace_Strategy.pdf.
[85] CISWG (2004). Corporate Information Security Working Group, Report of the Best Practices and Metrics Teams. Retrieved December 1, 2005 from http://www.educause.edu/ir/library/pdf/CSD3661.pdf.
[86] Information Security Management References. Retrieved December 1, 2005 http://reform.house.gov/UploadedFiles/Best%20Practices%20Bibliography.pdf.
[87] Emily Frye, “Cybersecurity and Corporate Governance Now: Does It Take Liability to Get Attention?”, in American Bar Association, Section Of Science & Technology Law, Chicago 2005, Retrieved December 1, 2005 from http://www.documation.com/aba/pdfs/004.pdf. Note: “[…] Adam Putnam (R-FL) circulated a draft of a bill he contemplated introducing in the House. Titled the Corporate Information Security Accountability Act (CISAA), it would have imposed information security audit reporting by all publicly traded companies. Adam Putnam, as Chair of the Subcommittee on Technology, Information Policy, Intergovernmental Relations and the Census (under the umbrella of the Committee on Government Reform), had become increasingly concerned about what he perceived to be apathy toward a cybersecurity crisis on the part of corporate America. Contemplation of a bill like CISAA set off an uproar among the private sector. Within weeks, almost every industry coalition that plays in this space was attacking the bill. On December 5, 2003, Adam Putnam convened the first meeting of a new coalition: The Corporate Information Security Working Group (CISWG). Putnam asked two questions: what's wrong with the draft of the bill? And – can you offer me a viable private-sector- led alternative to Congressional action?".
[88] United States Sentencing Commission (2003), Report to Congress: Increased Penalties for Cyber Security Offenses (As required by section 225(c) of the Homeland Security Act of 2002, Public Law 107-296). Retrieved December 1, 2005 from http://www.ussc.gov/r_congress/cybercrime503.pdf. Note: Report includes names Dan Swanson, Mike Hines.
[89] GAO Accounting and Information Division (1999). FISCAM, Federal Information System Controls Audit Manual Volume I: Financial Statement Audits, Washington: Government Accountability Office. Retrieved December 1, 2005 from http://www.gao.gov/special.pubs/ai12.19.6.pdf.
[90] CSRC CSD, Computer Security Resource Center's Computer Security Division. "With the passage of the Federal Information Security Management Act (FISMA) of 2002, there is no longer a statutory provision to allow for agencies to waive mandatory Federal Information Processing Standards (FIPS). The waiver provision had been included in the Computer Security Act of 1987; however, FISMA supersedes that Act. Therefore, the references to the "waiver process" contained in many of the FIPS listed below are no longer operative.
Note, however, that not all FIPS are mandatory; consult the applicability section of each FIPS for details. FIPS do not apply to national security systems (as defined in FISMA)". Retrieved December 1, 2005 from http://csrc.nist.gov/publications/fips/.
[91] Dr. Ron Ross & NIST. Protecting Federal Information Systems and Networks, A Standards-based Security Certification Program for Operational Environments. Retrieved December 1, 2005 from http://cio.doe.gov/Conferences/Security/Presentations/RossRNIST.pps.
[92] Dr. Ron Ross & The OWASP Foundation. Building More Secure Information Systems, A Strategy for Effectively Applying the Provisions of FISMA. Retrieved December 1, 2005 from http://csrc.nist.gov/organizations/fissea/conference/2005/presentations/Ross/Abstract-Ross.pdf.
[93] Charles Darwin, The Origin of Species (1859), London: J. Murray.
[94] ISO TC Portal. Standards Development Processes. Retrieved December 1, 2005 from http://isotc.iso.org/livelink/livelink/fetch/2000/2122/3146825/4229629/sds_base.htm.
[95] Idem.
[96] ISO & CASCO, ISO/IEC Guide 60:2004 Conformity Assessment -- Code of Good Practice, Geneva: ISO Store. Retrieved December 1, 2005 from http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=37035&ICS1=3&ICS2=120&ICS3=20&showrevision=y.
[97] NSSN, National Standards Systems Network. STAR, Standards Tracking and Automated Reporting, Services. Retrieved December 1, 2005 from http://www.nssn.org/star_intro.html.
[98] NISO, National Information Standards Organization. Retrieved December 1, 2005 http://www.niso.org/index.html.
[99] NISO. About ISO Technical Information and Documentation Committee 46. Retrieved December 1, 2005 from http://www.niso.org/international/TC46/index.html.
[100] ISO. General information on technical committees. Retrieved December 1, 2005 from http://www.iso.ch/iso/en/stdsdevelopment/tc/TC.html.
[101] ISO. "Achieving Optimal Output", in ISO Annual Report 2004, 2004, Chapter 4. Retrieved December 1, 2005 from http://www.iso.ch/iso/en/aboutiso/annualreports/pdf/chapter4.pdf.
[102] ISO. The Agreement on technical cooperation between ISO and CEN (Vienna Agreement). Retrieved December 1, 2005 from http://isotc.iso.org/livelink/livelink.exe/fetch/2000/2122/3146825/4229629/4230450/4230458/customview.html?func=ll&objId=4230458&objAction=browse&sort=subtype. Note: This is summarized by ISO as follows: “The Agreement on technical cooperation between ISO and CEN (Vienna Agreement) is an agreement on technical cooperation between ISO and the European Committee for Standardization (CEN). Formally approved on 27 June 1991 in Vienna by the CEN Administrative Board following its approval by the ISO Executive Board at its meeting on 16 and 17 May 1991 in Geneva, it replaced the Agreement on exchange of technical information between ISO and CEN" (Lisbon Agreement) concluded in 1989. The 'codified' Vienna Agreement was approved by ISO Council and the CEN Administrative Board in 2001.”
[103] United States Congress, "National Technology Transfer and Advancement Act of 1995'', in Public Law 104-113, H.R. 2196 & Congressional Record Vol. 141 (1995), Washington: U.S. Government Printing Office, 110 STAT. 775-784.
[104] ANSI. U.S. National Conformity Assessment Principles. Retrieved December 1, 2005 from http://www.ansi.org/conformity_assessment/ncap.aspx?menuid=4. Note: "The National Conformity Assessment Principles for the United States articulates the principles for U.S. conformity assessment activities that the consumer, buyers, sellers, regulators and other interested parties should be aware of to have confidence in the processes of providing conformity assessment, while avoiding the creation of unnecessary barriers to trade. We base these principles on the conformity assessment language in the Agreement on Technical Barriers to Trade, one of the agreements within the World Trade Organization (WTO).
[1] These principles supplement the language of the agreement to give national clarity and focus to conformity assessment in the United States. We intend the concise and clear presentation of these principles for the United States to promote national and international understanding and recognition of competently conducted U.S. conformity assessment processes resulting in increased acceptance of U.S. products.
[2] Within national and international markets. National and international acceptance is vital to the continued economic health of the United States, as well as to the protection of human health, safety and the environment. Because standards underlie all conformity assessment activities, this document is intended to be a companion to the principles of the U.S. standards system as described in the 'National Standards Strategy for the United States.' These two sets of principles should be considered together in the evaluation of standards and conformity assessment activities and related issues".
[105] ITTF, ISO/IEC Information Technology Task Force. Retrieved December 8, 2005 http://isotc.iso.org/livelink/livelink/fetch/2000/2489/Ittf_Home/ITTF.htm. Note: ITTF maintains access to all freely available ISO standards, a list that grows daily, and on December 8, 2005 included 253 free ISO standards.
[106] ITGI & OGC, Aligning COBIT®, ITIL® and ISO 17799 for Business Benefit, op.cit.
David A. Richards, CIA, President, The IIA, Alan S. Oliphant, MIIA, QiCA, MAIR International, and Charles H. Le Grand, CIA, CHL Global are listed as primary writers for GTAG; Global Technology Audit Guide; Information Technology Controls. Notable contributions by Corporations include Tripwire, ACL, and BindView, Note: Michael S. Hines, CIA, Purdue University, Julia H Allen, CMU/SEI Carnegie-Mellon University/Software Engineering Institute, Gene Kim, CTO, Tripwire Inc., USA, George Spafford Jr., President, Spafford Global Consulting, and Dan Swanson, CIA, IIA are again in the mix of contributors, innovators, Eagles and Humans.
[107] Euclid of Alexandria is the “most prominent mathematician of antiquity” as explained by http://www-groups.dcs.st-and.ac.uk/~history/Mathematicians/Euclid.html. He is only mentioned for having been named on the cover of most High School Algebra One text books.
[108] Lawrence W. Smith, "The FASB’s Efforts Toward Simplification", in The FASB Report, February 28, 2005. Retrieved December 1, 2005 from http://www.fasb.org/articles&reports/fasb_efforts_toward_simplification_tfr_feb_2005.pdf. Note: This article summarizing Bob Herz, FASB chairman of Financial Accounting Standards Board to show the complexity of GAAP as it relates to application of consistent standards and codification in the current 180 of US GAAP articles within U.S. Code.
[109] VISA International Service Association. Security Programs. Retrieved December 1, 2005 from http://corporate.visa.com/st/programs.jsp. Note: “Visa has collaborated with other payment card companies to create a single set of worldwide requirements, called the Payment Card Industry (PCI) Data Security Standard, for consumer data protection across the entire industry. The PCI Data Security Standard aligns Visa's Account Information Security (AIS) program, also known as Cardholder Information Security Program (CISP) in the U.S., and MasterCards' Site Data Protection (SDP) program, streamlining requirements, compliance criteria and validation processes. It also addresses merchants' and acquirers' concerns about having to meet more than one set of standards to accomplish a single goal.” © Copyright 1996-2005, Visa International Service Association.
[110] ISO. Standards and/or guides of TC 68/SC 2. Retrieved December 1, 2005 from http://www.iso.org/iso/en/stdsdevelopment/tc/tclist/TechnicalCommitteeStandardsListPage. TechnicalCommitteeStandardsList?COMMID=2193. Note: Standards in the last three years, by the Security management and general banking operations, are listed here as:
ISO 8732:1988/Cor 1:1999
ISO 9564-2:2005 Banking -- Personal Identification Number management and security -- Part 2: Approved algorithms for PIN encipherment
ISO 9564-3:2003 Banking -- Personal Identification Number management and security -- Part 3: Requirements for offline PIN handling in ATM and POS systems
ISO/TR 9564-4:2004 Banking -- Personal Identification Number (PIN) management and security -- Part 4: Guidelines for PIN handling in open networks
ISO 11568-1:2005 Banking -- Key management (retail) -- Part 1: Principles
ISO 11568-2:2005 Banking -- Key management (retail) -- Part 2: Symmetric ciphers, their key requirements and evaluation methods
ISO 13491-2:2005 Banking -- Secure cryptographic devices (retail) -- Part 2: Security compliance checklists for devices used in financial transactions
ISO 15782-1:2003 Certificate management for financial services -- Part 1: Public key certificates
ISO 16609:2004 Banking -- Requirements for message authentication using symmetric techniques
ISO/TR 17944:2002 Banking -- Security and other financial services -- Framework for security in financial systems
ISO/TR 19038:2005 Banking and related financial services -- Triple DEA -- Modes of operation Implementation guidelines.
[111] Skadden Biography. Michael S. Hines. Retrieved December 1, 2005 from http://www.skadden.com/index.cfm?contentID=45&bioID=2732. Note: Michael S. Hines has dedicated himself to distribution of accurate, timely security information, making about as much as anyone could from a career in Systems Administration at Purdue University (West Lafayette, IN). It seems hard to believe that with all he writes, he spend his own share of time putting out fires, just like the rest of us. It was a post by Mike that led me to the Common Criteria project. http://archives.neohapsis.com/archives/win2ksecadvice/1999-q4/0188.html, tipping off his peer group to Commercial Product Evaluations Main Page as early as 1999! Perhaps this is why Purdue’s infrastructure systems administrator, entrusted with their entire IT Infrastructure, was named president of the Central Indiana Information Systems and Control Association, an organization with more than 35,000 members. Watching Mike makes me feel like a potato!
[112] United States Congress & Subcommittee on Technology, Information Policy, Intergovernmental Relations and the Census (2004). Oversight Hearing Statement by Adam Putnam, Chairman, Identity Theft: The Causes, Costs, Consequences, and Potential Solutions. Retrieved December 1, 2005 from http://www.reform.house.gov/UploadedFiles/Final%20Press%20Opening%20Statement%202.pdf, p. 5.
[113] GTAG, op.cit, p. 17.
[114] Joseph Gibaldi (2003). MLA Handbook for Writers of Research Papers, 6th Edition. Retrieved December 1, 2005 from http://www.mla.org/handbook. & APA (2001). Publication Manual of the American Psychological Association, 5th Edition. Retrieved December 1, 2005 from http://www.apastyle.org/pubmanual.html.
[115] NIST Information Technology Laboratory (2002), International Standard ISO/IEC 17799:2000 Code of Practice for Information Security Management, Frequently Asked Questions, Retrieved December 1, 2005 from http://csrc.nist.gov/publications/secpubs/otherpubs/reviso-faq.pdf.
[116] ITTF. Freely Available Standards. In accordance with ISO/IEC JTC 1 and the ISO and IEC Councils these International Standards are publicly available. Retrieved December 1, 2005 from http://isotc.iso.org/livelink/livelink/fetch/2000/2489/Ittf_Home/ITTF.htm. Note: The standards are available for download at the ITTF web site. This does not imply free use or permission to copy any materials found. The files are in zip format. I had no difficulty with them but always use a staging are to run additional anti-virus/spyware before opening anyone’s files: http://standards.iso.org/ittf/PubliclyAvailableStandards/c040612_ISO_IEC_15408-1_2005(E).zip, http://standards.iso.org/ittf/PubliclyAvailableStandards/c040613_ISO_IEC_15408-2_2005(E).zip, & http://standards.iso.org/ittf/PubliclyAvailableStandards/c040614_ISO_IEC_15408-3_2005(E).zip.
[117] Note: Product evaluation results in certification and explanation of product compliance with acknowledge best practice and industry standards for certification as required by any type of company or branch of government or international service. Tripwire Manager 3.0 with Tripwire for Servers 3.0, Tripwire Manager 3.0 with Tripwire for Servers Check Point Edition 3.0, a product heavily supported by the IIA has listed certification since 2003.
[118] CESG (UK) & NIST (USA). Common Criteria, An Introduction. Retrieved December 1, 2005 from http://www.commoncriteriaportal.org/public/files/ccintroduction.pdf. Note: "The Common Criteria work is an international initiative by the following organizations: CSE (Canada), SCSSI (France), BSI (Germany), NLNCSA (Netherlands), CESG (UK), NIST (USA) and NSA (USA)", p. 2.
[119] Ibid., p. 6.
[120] Tim O'Reilly, What Is Web 2.0, Design Patterns and Business Models for the Next Generation of Software, 09/30/2005 Retrieved December 30, 2005 from http://www.oreillynet.com/pub/a/oreilly/tim/news/2005/09/30/what-is-web-20.html?page=1, What is Web 2.0
[121] Idem, Article cites: Daniel Bricklin, The Cornucopia of the Commons: How to get volunteer labor, © Copyright 1999-2005, Retrieved December 31, 2005 http://www.bricklin.com/cornucopia.htm.
[122] OASIS (2005). Security Assertion Markup Language (SAML) v2.0. Retrieved December 1, 2005 from http://www.oasis-open.org/specs/index.php#samlv2.0, & http://docs.oasis-open.org/security/saml/v2.0/saml-2.0-os.zip.
[123] DocBook Schemas. Retrieved December 1, 2005 http://docbook.org/oasis/index.html. Note: As stated on the website: “DocBook is a schema (available in several languages including RELAX NG, SGML and XML DTDs, and W3C XML Schema) maintained by the DocBook Technical Committee of OASIS. It is particularly well suited to books and papers about computer hardware and software (though it is by no means limited to these applications)."
[124] Norman Walsh & Leonard Muellner, DocBook: The Definitive Guide, O'Reilly & Associates, Inc., Version 1.0.2 (1999). Retrieved December 1, 2005 from http://www.oreilly.com/catalog/docbook/chapter/book/docbook.html. Note: This is the official documentation for DocBook. & Bob Stayton, DocBook XSL: The Complete Guide, Sagehill Enterprises, Third Edition (2005). Retrieved December 1, 2005 from http://www.sagehill.net/docbookxsl/. Note: This is the definitive guide to using the DocBook XSL stylesheets. It provides the necessary documentation to realize the full potential of DocBook publishing. It covers all aspects of DocBook publishing tools, including installing, using, and customizing the stylesheets and processing tools.
[125] The phrase "apples and oranges," is not mine, but the source cannot be found at this time. Interesting to note, is an article by Scott Berinato found at Darwin, The Chief Security Officer magazine/ website, where attempted to find the origin of this phrase. http://www.darwinmag.com/read/0502/apples.html.
[126] United States Congress, "Computer Security Enhancement Act of 1997", in Public Law 100-418, H.R. 1903, Calendar No. 718, & Report No. 105-412 (1998), SEC. 1-14. Note: "To amend the National Institute of Standards and Technology Act to enhance the ability of the National Institute of Standards and Technology to improve computer security, and for other purposes."
[127] Payment Card Industry (PCI) Data Security Standard, op.cit.
[128] PricewaterhouseCoopers, Integrity Driven Performance, White Paper (2004), Page 34, Note: PricewaterhouseCoopers (www.pwc.com) provides industry-focused assurance, tax and advisory services for public and private clients. More than 120,000 people in 139 countries connect their thinking, experience and solutions to build public trust and enhance value for clients and their stakeholders.
[129] Note: While providing support to our CISA study group, Bruce I Winters CPA, CISA of, PricewaterhouseCoopers LLP – CT, shared this work (and a wealth of industry knowledge). Sustainable compliance is a new domain for the integration of all IT Infrastructure and Enterprise Management. The topic has provoked tremendous advance in the concepts of configuration and process, aiding entire divisions of study to every institution of learning and changing the way we think about the creation of even the smallest snippet of code for the simplest of devices.
[130] Stanley Kubrick & Arthur C. Clarke, “HAL 9000” or “HAL”, in 2001: A Space Odyssey, USA Box Office: MGM Home Entertainment, 1968.
[131] Tom Gruber, What is an Ontology?, KSL, Knowledge Systems, AI Laboratory, Stanford University. Retrieved December 1, 2005 from http://www-ksl.stanford.edu/kst/what-is-an-ontology.html. Note: “An ontology is an explicit specification of a conceptualization. […] We use common ontologies to describe ontological commitments for a set of agents so that they can communicate about a domain of discourse without necessarily operating on a globally shared theory."
[132] NIST SP 800-53 Database Application is available for download at http://csrc.nist.gov/sec-cert/download-800-53database.html.
[133] OntoWeb Project, OntoWeb Working Group on Process Standards. Retrieved December 1, 2005 from http://www.aiai.ed.ac.uk/project/ontoweb/. Amy Knutilla, Craig Schlenoff, Steven Ray, Stephen T. Polyak, Austin Tate, Shu Chiun Cheah and Richard C. Anderson: "Process Specification Language: An Analysis of Existing Representations," NISTIR 6160, National Institute of Standards and Technology, Gaithersburg, MD, 1998.
[134] OGC, ICT Infrastructure Management Manual, op.cit., Section 2.7, pp. 59-63.
[135] Idem.
[136] PricewaterhouseCoopers on behalf of COSO, COSO, Enterprise Risk Management — Integrated Framework, AICPA, Volume 2. Retrieved December 1, 2005 from https://www.cpa2biz.com/CS2000/Products/CPA2BIZ/Publications/COSO+Enterprise+Risk+Management+-+Integrated+Framework.htm. & COSO (2005), Internal Control — Integrated Framework. & Guidance for Smaller Public Companies Reporting on Internal Control over Financial Reporting, AICPA, Exposure Draft. Retrieved December 1, 2005 from http://155.201.80.182/Coso/coserm.nsf/vwResources/PDF_IC/$FILE/COSO_FINAL_Draft_IC_Guidance.pdf. Note: These are both noted by the SEC as appropriate framework in the implementation of controls assessment.
[137] Note: Google is a fascinating company, but their name is not “Googol”, confused infinite number. I am reminded by the PBS rerun of Cosmos, of Carl Sagan saying the googol is finite in number with 1 followed by 100 zeros, or 10100.
[138] ITGI & ISACA (2004). COBIT® Mapping, Overview of International IT Guidance. Retrieved December 1, 2005 from http://www.isaca.org/Content/ContentGroups/Research1/Deliverables/CobiT_Mapping_Paper_6jan04.pdf.
[139] ITGI & ISACA (2004). It Control Objectives for Sarbanes-Oxley: The Importance of It in the Design, Implementation and Sustainability of Internal Control over Disclosure and Financial Reporting. Retrieved December 1, 2005 from http://www.isaca.org/Content/ContentGroups/Research1/Deliverables/IT_Control_Objectives_for_Sarbanes-Oxley_7july04.pdf.
[140] Idem.
[141] FERF, Financial Executives Research Foundation. Retrieved December 1, 2005 http://www.fei.org/rf/.
[142] ISACA, ISACA Membership Information. Retrieved November 1, 2005 http://www.isaca.org/Template.cfm?Section=Membership&Template=/TaggedPage/TaggedPageDisplay.cfm&TPLID=15&ContentID=7510.
[143] AICPA Membership. AICPA 2004-2005 Annual Report. Retrieved November 1, 2005 from http://www.aicpa.org/about/annrpt/2004-2005/aicpa_04-05_ar.pdf, p. 22.
[144] IIA, op.cit.
[145] U.S. Department of Labor, Bureau of Labor Statistics. Occupational Employment and Wages, November 2004. Retrieved December 1, 2005 from http://www.bls.gov/oes/current/oes132011.htm.
[146] NASB, National Association of State Boards of Accountancy. Retrieved November 1, 2005 http://www.nasba.org/nasbaweb.nsf/?Open.
[147] ACLU, (American Civil Liberties Union). Free Speech. Retrieved November 1, 2005 from http://www.aclu.org/freespeech/index.html.
[148] Edwards Deming (1986), "14 Points for Management", in Out of Crisis, 1986, Cambridge: The MIT Press. Retrieved December 1, 2005 from http://www.deming.org/resources/books.html. Note: Found at http://www.deming.org/instituteinfo/wedihistory.html, “The W. Edwards Deming Institute® was founded by Dr. Deming in 1993. The Institute is headquartered in Washington, D.C. It is a nonprofit corporation which provides educational services related to the teachings of Dr. Deming. These services include conferences and seminars. The Institute also makes Dr. Deming's personal and professional papers available to researchers at the U.S. Library of Congress. The Deming Collection at the Library of Congress includes an extensive audiotape and videotape archive of Dr. Deming. The aim of The W. Edwards Deming Institute® is to foster understanding of The Deming System of Profound Knowledge™ to advance commerce, prosperity and peace."
[149] U.S. Navy, "Increasing Contractor Commitment", in Benefits, DoN Acquisition One Source. Retrieved from December 1, 2005 http://www.ar.navy.mil/aosfiles/tools/turbo/topics/cj.cfm. Note: Argument promotes the works of Edwards Deming as reason for DoD changes in procurement and acquisition practice.
[150] Deming, op.cit. Chapter 2. Note: Edwards Deming, author of Out of the Crisis and The New Economics and father of Quality Management – Perhaps, best known for “14 points for Management”. The Edwards Deming Institute, "Condensation of the 14 Points for Management", in The Deming System of Profound Knowledge (Continued). Retrieved December 1, 2005. (not my Dad) (real Dad) I sincerely apologize to any member of the actual Deming family. What I said was, "My Dad is "TQM" This is true. He worked for International Telephone & Telegraph, ITT, during the 60s and up to the 80's during the era of CEO "No Surprises", "leadership through action" Harold Geneen. My Dad's full name is... Alvin Martin Silver. I still like to call him TQM. I also said I wish I had been raised by wolves. I meant to disrespect to dogs or my own family.
[151] Get the Data and Proportionality
[152] The Fog of War
[153] Morris explains in NPR interview that reading Paul Hendrickson book.
[154] You can't change human nature.
[155] The Fog of War included Robert McNamara’s recit.
[156] Rudyard Kippling’s Law For Wolves. Note: Joseph Rudyard Kipling (December 30, 1865 – January 18, 1936) was a British author and poet, born in India. He is best known for the children's story The Jungle Book (1894), the Indian spy novel Kim (1901), the poems "Gunga Din" (1892) and "If— " (1895), and his many short stories. In 1907 he was awarded the Nobel Prize for Literature, and in 1934 he shared the Gothenburg Prize for Poetry with William Butler Yeats.
[157] Note: Recently, while preparing to take the CISA exam, a download found way to my inbox claiming 600 study examples based in the 2005 information audit competency requirements. They were an export of the ISACA study manual questions, not only under copyright but representing critical revenue to an important organization. I was outraged. ISACA enforced the removal of the distributed material, but not before it had been downloaded.
[158] Note: Contributing member to far too many publications, it is notable that Tom Lamm was part of The World Bank Technology Risk Checklist 6.0, a highly organized overview for assurance of implemented banking security practice. Published by The World Bank in 2003, Tom worked with a team that included Julia Allen. It’s that pattern again, of good minds showing up for all the most important occasions.
[159] Charles Le Grand, CIA, CISA, CDP,
[160] Richard P. Feynman & Jeffrey Robbins, The Pleasure of Finding Things Out, Cambridge: Perseus Publishing, 1999, p. 1.
[161] Note: This analogy is not alluding Sarbanes-Oxley being extricated by congress like a large pile of dung. That would lack respect. The sprouting of mushrooms on dung, are the “self proclaimed control experts” selling compliance service based in FUD tactics (Fear, Uncertainty, Doubt).
[162] Note: Efforts to keep ISO adapting are so pervasive that this would merit a full thesis of information on its own.
[163] EDUCAUSE. Information Security Governance Assessment Tool For Higher Education. Retrieved December 1, 2005 from http://www.educause.edu/ir/library/pdf/SEC0421.pdf.
[164] EDUCAUSE & Internet2. Computer and Network Security Task Force. Retrieved December 1, 2005 from http://www.educause.edu/Elements/Attachments/security/flyer.pdf. Note: "Established by EDUCAUSE and Internet2 in July 2000, the Computer and Network Security Task Force works to improve awareness among the EDUCAUSE and Internet2 memberships and throughout higher education and actively promotes effective practices and solutions for the protection of information assets and critical infrastructures. The Security Task Force coordinates its efforts on behalf of institutions of higher education with the support of the Higher Education Information Technology Alliance (www.heitalliance.org), whose members include the American Association of Community Colleges, the American Association of State Colleges and Universities, the American Council on Education, the Association of American Universities, the National Association of Independent Colleges and Universities, and the National Association of State Universities and Land-Grant Colleges."
[165] Public Law 104-13 http://www.educause.edu/ir/library/pdf/SEH. As explained on their web site: EDUCAUSE and Internet2 established the Computer and Network Security Task Force in July 2000. The Task Force is working to improve awareness among the EDUCAUSE and Internet2 memberships and throughout higher education. The Security Task Force actively promotes effective practices and solutions for the protection of information assets and critical infrastructures. The Security Task Force is coordinating its efforts on behalf of institute.
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics