Thursday, June 14, 2007

Watch Your Breaches: Protect Laptops

Financial firms have some viable options for securing laptops from data breach / identity theft. ...

... "Maybe the data isn't worth the price of securing the computer, but for most financial services companies there are no excuses. The options for securing laptops are expanding and in many cases getting more practical for broader use. " ...


Via Wall Street & Technology: Laptop Threat

Labels: , , , , ,

Thursday, April 26, 2007

Project Business Case: Watch List

Feds make progress in managing down project gaps as watch list volume decreases. ...

... "The management watch list highlights weak business cases for hundreds of government IT projects. The projects are considered at risk because of deficient acquisition strategies, poor data security measures or flawed design plans. " ...


Via Federal Times: Project Business Case and Watch List

Labels: , , , , ,

Tuesday, December 12, 2006

Data Security Breach: High Impact Public Event

UCLA discusses its data security breach
UCLA deals with painful security event in open, transparent way. The security investigation shows that the security breach was exploited to seek Social Security numbers and started as early as October 2005. The university has established a website specifically to handle this event. ...

... "UCLA is alerting approximately 800,000 people that their names and certain personal information are contained in a restricted database that was illegally and fraudulently accessed by a sophisticated computer hacker. " ...


Via UCLA: UCLA Warns of Unauthorized Access to Restricted Database

Labels: , , ,

Tuesday, November 21, 2006

IT Governance: Data Security Matters

Take data security seriously and dedicate time in the IT governance agenda for it. Define security policy and create roles / accountability for it through postion of information security officer. ...

... "Formalize an IT governance process with documented policies and controls. Representatives from different departments, including IT, should develop this manual together as a task force led by the ISO. " ...


Via Miami Herald: Link

Labels: , , , , , ,

Sunday, November 05, 2006

Asset Management: Secure, Track Your Laptops

A number of interesting experiences and lessons are at play here for Starbucks ... The need for better security of private employee data. Traceability of its information technology assets. In this case, the company is not even sure that the assets are out of its possession. And, finally, transparency. Starbucks is being pretty open about the situation, as embarrassing as it is. They'll learn and improve from the experience. ...

... "Starbucks Corporation announced that four retired (no longer in regular use) laptops have been identified as missing from the Starbucks Corporate Support Center in Seattle. Two of the laptops contained the private information, including names and social security numbers, of nearly 60,000 United States partners (employees) and less than 80 Canadian partners and contractors at all levels employed across the organization prior to Dec.31, 2003. At this time, there is no indication that the private information in question has been misused or that the devices are in the hands of someone intending to misuse the information. These laptops may still be in the possession of Starbucks, however we cannot currently locate them. In accordance with Starbucks standards for information security, the laptops were password protected. " ...


Via Starbucks: Link

Labels: , , ,

Wednesday, November 23, 2005

The New ISO 27001 Security Standard; Get Prepared! Listen to Alan Calder's Podcast

As I've mentioned before, the perfect storm is headed our way. As more companies move toward hosted solutions and the threat of a pandemic computer virus looms, organizations worldwide could be crippled.

Enter the new ISO 27001 Security Standard.

Alan Calder, the leading IT Governance and Security expert and CEO of IT Governance, Ltd., issued a podcast last week talking about ISO 27001 and its impacts. Best of all, Calder offers several eBooks for all levels of audiences, as well as an ISO 27001 toolkit, which allows organizations to become ISO 27001-compliant without expensive consultants.

Here's what Calder's company, IT Governance Ltd. has to say about the new standard:

  • ISO 17799:2005 and BS 7799 are the international best practice information security management standards, defining and guiding Information Security Management System (ISMS) development.
  • BS7799 is the basis for the new international standard ISO 27001, which was introduced in October 2005. Internationalisation will create a global upsurge in demand for ISMS certification.
  • ISO 27001 will become the international touchstone for effective, secure information management practices that protect organisations and ensure their compliance with data protection, privacy and computer misuse regulations.
  • As with ISO 9000, the new standard will become a prerequisite for many businesses wishing to secure new customers and contracts. It is therefore as much a business issue as an IT issue.

    To learn more, check out Alan Calder's podcast below...

    Alan Calder on IT Governance, information security and ISO 27001 (BS7799): Talking ISO 27001

Labels: , , , , , , , ,

Tuesday, November 01, 2005

Enterprise Architecture: SEC Future State: Troux Metis ...

Troux and ISI partner to drive the enterprise architecture transformation at the SEC over the next few years. ...

Enterprise Architecture: SEC Future State: Troux Metis: Via Troux: SEC Taps Troux Technologies and ISI for Multi-Year Enterprise Architecture Program

... "Troux Technologies, the global leader in IT Governance and Enterprise Architecture (EA) solutions, and Integrated Systems, Inc., a foremost 8(a)-certified systems integrator, announced they have jointly won a multi-year contract from the U.S. Securities and Exchange Commission to implement the SEC's Enterprise Architecture and increase its business value. Under the agreement, Troux and ISI will collaborate to provide the SEC's Office of Information and Technology with consulting expertise in documenting the SEC's current state architecture, and in developing and maintaining future state target architectures. ... Troux's Metis Enterprise is an Enterprise Architecture and planning solution that provides the basis for the transformation from an organization's current state to an optimized future state. It is designed with a highly scalable database that accommodates the volume of enterprise-wide data required for successful organizational transformation. Additionally, Troux's Metis offers a unique analysis capability, leveraging both the current and future EA states. The automated data collection in Metis, from disparate sources across the organization, keeps information timely and relevant. " ...


Troux's Metis will be used to model the future state enterprise architecture at the SEC ...

Integrated Systems, Inc. is dedicated to the development and implementation of high quality technology- and process-based solutions for government and commercial clients. Founded by Indrani Seetharam in 2000, ISI is a Minority Woman-Owned 8(a)-Certified small business, currently providing sophisticated technical solutions to the U.S. Treasury, the Departments of Homeland Security (US VISIT Program), Transportation (National Highway Traffic Safety Administration), Energy, Agriculture and Education; the National Archive and Records Administration; the State of Delaware; and the US Navy Space Warfare Center (SPAWAR). ISI's focus areas include Enterprise Architecture, Information Assurance, Information Security, Certification and Accreditation, Independent Validation and Verification and Life-cycle Management. ISI develops practical, affordable, and deliverable solutions of significant value to its clients, on or ahead of schedule.

Troux Technologies (pronounced "true") is a global provider of IT Governance software that accelerates IT and business transformation. Troux's IT Governance solutions enable organizations to strategically plan the enterprise, capture and analyze critical IT and business data and deliver actionable decisions to transform the business. Troux's breakthrough technology provides the enterprise-class information, policies, and analytics critical for IT excellence. With Troux, organizations succeed in breaking the traditional IT silos and effectively aligning IT with core business goals. Based in Austin, Texas, Troux Technologies serves the Global 1000 and government marketplaces.

Labels: , , , , , , , , , , , , , , ,

Wednesday, October 12, 2005

IT Service Delivery Management: Excellence Model

Ah!, the sweet taste of ITSM IT services management ... Hershey's adopt Sun Micro's service excellence model to improve the delivery of business value. Sun has developed a portfolio of aligned IT services, called SunTone. ...

IT Service Delivery Management: Excellence Model: Via Sun Microsystems: The Hershey Company Continues To Use Sun Microsystems' SunTone Service Excellence Model to Improve IT Service Delivery Management ...

... "Sun Tone is part of Sun's integrated portfolio of aligned services that provide IT infrastructure planning, assessments, and resolution services for customer business issues. SunTone helps enterprises derive greater business value from IT, transforming IT from a support function to a provider of business-led services that create competitive advantage. SunTone Service Excellence Model provides guidance and a measurement system for Sun Tone users. The new SunTone Service Excellence Model 3.0 brings advancements in industry standard and regulatory compliance, major enhancements in security, greater manageability, and requirements for financial management.

By adopting the SunTone Service Excellence Model and consistently operating enterprise data center services in accordance with SunTone certification requirements, Hershey was able to improve service availability and operational efficiency. Hershey was also able to reduce the time and effort required to meet requirements for IT governance. Hershey's experience is representative of a current global market trend to adopt IT service management (ITSM) principles to improve IT governance, compliance, drive operational efficiencies and derive greater business value from IT. The SunTone Service Excellence Model covers all the elements involved in delivering IT services -- system architecture, operational processes, and human skills. " ...


The Hershey Company (NYSE: HSY) is a leading snack food company and the largest North American manufacturer of quality chocolate and non-chocolate confectionery products. With revenues of over $4 billion and more than 13,000 employees worldwide, The Hershey Company markets such well-known brands as Hershey's, Reese's, Hershey's Kisses, Kit Kat, Almond Joy, Mounds, Jolly Rancher, Twizzlers, Ice Breakers, and Mauna Loa, as well as innovative new products such as Take 5 and Hershey's Cookies.

Labels: , , , , , , , , , , , ,