Services
Services
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Enterprise Governance Risk & Compliance
Does Audit Make Us Secure? Presented at ISACA SV Spring Conference, May 15th, 2015 - (I totally stand by the content.). Presented by Robin Basham, M.Ed., M.IT, CISSP, CISA, CRISC, CGEIT, HISP, CRP, VRP, Founder EnterpriseGRC Solutions. Companies that passed the audit and had a major breach could have survived with this approach.
- Hits: 995
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Enterprise Governance Risk & Compliance
Data Loss Prevention DLP – Ready or Not, By Robin Basham, CISSP, CISA, CRISC, CGEIT, M.Ed., M.IT
If you are required to comply with (US) HIPPA, State Social Security Laws, COPPA, State Security Breach Laws (California Civil Code § 1798.29, 1798.80 et seq.), GLBA or PCI-DSS, someone will ask you
- How many unauthorized data exfiltration attempts have been detected recently by the organization's Data Loss Prevention (DLP) system?
- What percentage of the organization's business systems are not utilizing host-based Data Loss Prevention (DLP) software applications?
- Whether it was a customer request or a conversation with an examiner, they expected a detailed answer broken out by the business unit. If you manage compliance, you are accountable to these answers.
- Good News: When done right, Data Loss Prevention – DLP benefits
- Protect critical business data and intellectual property
- Improve compliance
- Reduce data breach risk
- Enhance training and awareness
- Improve business processes
- Optimize disk space and network bandwidth
- Detect rogue/malicious software
- Hits: 979
- Details
- Written by: Robin Basham
- Parent Category: Enterprise Governance Risk & Compliance
- Category: ISMS / PIMS - ISO/IEC Certification Programs
Tools approach to automating ISO27002 ISMS Policy aligned continuous monitoring
Current ISO Offerings include
- ISO 13485:2016
- ISO/IEC 30111:2019
- ISO/IEC 27001:2013 €
- ISO/IEC 27017:2015 € 27002 for cloud services
- ISO/IEC 27799:2016 €
- ISO/IEC 27002:2013 € New ISO/IEC FDIS 27002 and mapping to CCM V4 and NIST 171 Assessment
- ISO/IEC 27018:2019 €
- ISO/IEC 27701:2019 €
- Hits: 1345
- Details
- Written by: Robin Basham
- Parent Category: Enterprise Governance Risk & Compliance
- Category: ISMS / PIMS - ISO/IEC Certification Programs
ISO/IEC 27001:2005 - now ISO/IEC 27002:2013
- Hits: 243
- FCM - Mapping & Fixing GRC
- Maturity vs. Compliance
- EnterpriseGRC Secure Cloud Solutions
- 4Point GRC™ - FCM - Our History and Foundation - The Architecture
- RunBook UML
- Privacy Preserving Analytics - Knowing the Experts is more important than you'd think (Ulf Mattsson)
- Data Centric Security & GDPR - Is Your Organization Ready (Seminar and Content)
- Privacy Resources - Facts, not Fiction
- Breach Notification and HIPAA
- Example of a Great Web Privacy Policy
