<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-987581787108127885</id><updated>2026-05-27T16:49:36.527-04:00</updated><category term="ISO 27001"/><category term="isms"/><category term="Axur Blog"/><category term="Gap Analysis"/><category term="Research"/><category term="controles"/><category term="eficiência"/><title type='text'>Real ISMS Official Blog - ISO 27001, SaaS &amp;amp; Software</title><subtitle type='html'>ISO 27001 ISMS - Information Security Management Solution (Software &amp;amp; SaaS) - www.realiso.com/realisms</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default?start-index=26&amp;max-results=25'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>108</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-8386837931376202974</id><published>2009-01-12T06:02:00.000-05:00</published><updated>2009-01-12T06:13:51.607-05:00</updated><title type='text'>ISO 27001 - The auditor’s perspective</title><content type='html'>&lt;p&gt;Hello readers,&lt;/p&gt; &lt;p&gt;Wish you all a very happy and prosperous 2009.&lt;/p&gt; &lt;p&gt;During the 2nd last week of 2009, I had a meeting with a prospective client who was interested in implementing an ISO 27001 compliant ISMS and getting it certified. One question which they asked was, “Can I see an ISO 27001 system?”. When I requested them to be specific, they said “You know..all the documents, policies, guidelines etc.”. What I could infer from the discussion was that they clearly thought it was a system which was documented.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Tangibles and intangibles in an ISO 27001 ISMS&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;I spend some time to explain to them that the ISO 27001 system consisted of tangibles and intangibles. There are things that you can see, touch and feel, but there are a lot of components that you cannot see, touch or feel. This prompted me to go back to some of my earlier experiences with ISO 27001 customers. In most cases, during the initial discussions, most customers were asking the question, “Can I see the ISO 27001 policies that you have created?” During ISO 27001 training sessions, they would invariably ask the question, “Can you give us some sample policies and sample templates using which we can create the policies?” And, when asked, why they were always asking for the policies upfront, the answer invariably would be, “Well, that is what we need to pass the audits and get certified right?” This prompted me to think more about this from the customers’ perspective and ask the question, “Are ISO 27001 audits (especially from a certification process) being misinterpreted for their purpose?”&lt;/p&gt; &lt;p&gt;&lt;strong&gt;The smart ISO 27001 auditor looks for..&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;No doubt, documentation is a very important component from a certification process, but from my perspective, an ISO 27001 auditor, will look for two things,&lt;/p&gt; &lt;p&gt;1 - The existence of the ISMS&lt;br /&gt;2 - The functioning of the ISMS&lt;/p&gt; &lt;p&gt;Let us examine, “Point 1 - The existence of the ISMS”. This essentially means whether the P-D-C-A (Plan-Do-Check-Act) model is in place and all the required components of the P-D-C-A model exists. This would start from the Scope, the security forum, the asset classification list, risk analysis approach, the actual risk analysis reports, acceptance of risk, risk treatment and actual proof of risk treatment, audits, reviews etc. Some of these components are tangibles and some of them are intangibles. The smart auditor will spend his time first verifying this.&lt;/p&gt; &lt;p&gt;Let us examine, “Point 2 - The functioning of the ISMS”. The functioning of the ISMS is verified through the review and improvement processes, which comes in the CHECK and ACT phase. The smart auditor will check the internal audit reports, and often ask the question &lt;strong&gt;“Have you done a root cause analysis?”&lt;/strong&gt; This is a very important question because the auditor is probing whether the organization has not just identified the problem, but has gone deep inside to check the root cause of the problem and then solve it. This proves that the ISMS is not just existing, but also functioning.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;The broad picture or the Top-level view&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;So, anyone who is getting ready for an ISO 27001 Implementation and Certification process, please keep the broad picture in mind. This will help you not to get off-track and will help you when you are in a dilemma at certain junctions of the ISO 27001 implementation cycle.&lt;/p&gt; &lt;p&gt;You will have a great ISO 27001 implementation, maintenance and certification experience if you focus on proving two factors.&lt;/p&gt; &lt;p&gt;1) I have an ISMS in my organization&lt;br /&gt;2) My ISMS is functioning well&lt;/p&gt; &lt;p&gt;&amp;amp; if you care to come and check, I shall prove both the above points to you. With this attitude you have a winner ISMS in your hands.&lt;/p&gt; &lt;p&gt;Warm regards,&lt;/p&gt; &lt;p&gt;Anup Narayanan&lt;br /&gt;www.isqworld.com (Learning ISO 27001 through storytelling)&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/8386837931376202974/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/8386837931376202974' title='32 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/8386837931376202974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/8386837931376202974'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2009/01/iso-27001-auditors-perspective.html' title='ISO 27001 - The auditor’s perspective'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>32</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-7711489612227273150</id><published>2009-01-12T05:57:00.002-05:00</published><updated>2009-01-12T06:02:19.945-05:00</updated><title type='text'>Key Strategies for Implementing ISO 27001</title><content type='html'>In 1995, the British Standard Institute (BSI) published British Standard (BS) 7799, a widely adopted set of best practices that help organizations implement effective information security management systems (ISMSs) and establish security controls for specific business areas. In October 2005, the standard was adopted by the International Organization for Standardization (ISO). As a result, implementing BS 7799 — now ISO 27001: 2005 — has become a major focus of attention for European-based companies and those working in the region.&lt;br /&gt;&lt;br /&gt;Depending on the organization&#39;s size, the nature of its business, and the maturity of its processes, implementing ISO 27001 can involve a substantial investment of resources that requires the commitment of senior management. In addition, because of its emphasis on data security, many internal auditors perceive the standard to be focused solely on technology and often recommend that IT departments comply with the standard&#39;s requirements without understanding the amount of time and resources required for compliance. To ensure across-the-board acceptance and success, initial analyses and planning are vital. Because internal auditors are in the perfect position to add value to an organization&#39;s IT processes, they can help IT departments prepare the groundwork for an effective and efficient ISO 27001 implementation strategy during the initial planning phase. This will help companies ensure their IT processes are better aligned with the standard&#39;s requirements and ensure long-term compliance.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;RECOMMENDATIONS FOR EFFECTIVE ISO 27001 COMPLIANCE&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Implementing ISO 27001 can take time and consume unforeseen resources, especially if companies don&#39;t have an implementation plan early in the compliance process. To enhance compliance efforts, internal auditors can help companies identify their primary business objectives and implementation scope. Auditors should work with IT departments to determine current compliance maturity levels and analyze the compliance process&#39; return on investment. These steps can be conducted by a team of staff members or external consultants who have prior experience implementing the standard. External consultants should work in collaboration with an internal team of representatives from the company&#39;s major business units. Below is a description of each recommendation.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Identify Business Objectives&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Plans to adopt ISO 27001 must be supported by a concrete business analysis that involves listing the primary business objectives and ensuring a consensus is reached with key stakeholders. Business objectives can be derived from the company&#39;s mission, strategic plan, and existing IT goals and may include:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Ensuring effective risk management, such as identifying information assets and conducting accurate risk assessments.&lt;/li&gt;&lt;li&gt;Maintaining the company&#39;s competitive advantage, if the industry as a whole deals with sensitive information.&lt;/li&gt;&lt;li&gt;Preserving the organization&#39;s reputation and standing among industry leaders.&lt;/li&gt;&lt;li&gt;Providing assurance to customers and partners about the organization’s commitment to protecting data.&lt;/li&gt;&lt;li&gt;    Increasing the company&#39;s revenue, profitability, and savings in areas where protective controls operate well. &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The standard also emphasizes compliance with contractual obligations, which might be considered another key business objective. For instance, for an online banking division, implementing the standard would provide customers and partners greater assurance that risks stemming from the use of information systems are managed properly.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Select the Proper Scope of Implementation&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Identifying the scope of implementation can save the organization thousands of dollars and time. In many instances, it is not necessary for an organization to adopt companywide implementation of a standard. The scope of compliance can be restricted to a specific division, business unit, type of service, or physical location. In addition, once successful compliance has been achieved for a limited, but relevant scope, it can be expanded to other divisions or locations.&lt;br /&gt;&lt;br /&gt;Choosing the right scope is one of the most important factors throughout the compliance cycle, because it affects the feasibility and cost of the standard&#39;s implementation and the organization&#39;s return on investment. As a result, it is important for the selected scope to help achieve the identified business objectives. To do this, the organization may evaluate different scope options and rank them based on how well they fit with each objective.&lt;br /&gt;&lt;br /&gt;Organizations also may want to sign memorandums of understanding (MOU) or service level agreements (SLAs) with vendors and partners to implement a form of indirect compliance to the standard. For example, a garment manufacturing company may have a contract with a software provider for application maintenance and upgrades. Therefore, the manufacturing company will not be responsible for the application’s system development life cycle compliance with the standard, as long as it has a relevant MOU or SLA signed with the software vendor.&lt;br /&gt;&lt;br /&gt;Finally, the organization&#39;s overall scale of operations is an integral parameter needed to determine the compliance process&#39; complexity level. To find out the appropriate scale of operations, organizations need to consider their number of employees, business processes, work locations, and products or services offered.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Determine ISO 27001 Maturity Levels&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;When assessing the organization’s compliance maturity level, auditors should determine whether or not the implementation team is able to answer the following questions:&lt;br /&gt;&lt;br /&gt;   &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Does a document exist that specifies the scope of compliance?&lt;/span&gt;&lt;br /&gt;     According to ISO 27001, a scope document is required when planning the standard&#39;s implementation. The document must list all the business processes, facilities, and technologies available within the organization, along with the types of information within the ISMS. When identifying the scope of compliance, companies must clearly define the dependencies and interfaces between the organization and external entities.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Are business processes and information flows clearly defined and documented?&lt;/span&gt;&lt;br /&gt;     Answering this question helps to determine the information assets within the scope of compliance and their importance, as well as to design a proper set of controls to protect information as it is stored, processed, and transmitted across various departments and business units.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Does a list of information assets exist? Is it current?&lt;/span&gt;&lt;br /&gt;     All assets that may affect the organization&#39;s security should be included in an information asset list. Information assets typically include software, hardware, documents, reports, databases, applications, and application owners. A structured list must be maintained that includes individual assets or asset groups available within the company, their location, use, and owner. The list should be updated regularly to ensure accurate information is reviewed during the compliance certification process.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;How are information assets classified?&lt;/span&gt;&lt;br /&gt;     Information assets must be classified based on their importance to the organization and level of impact, and whether their confidentiality, availability, and integrity could be compromised.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Is a high-level security policy in place?&lt;/span&gt;&lt;br /&gt;     Critical to implementing an information security standard is a detailed security policy. The policy must clearly convey management&#39;s commitment to protecting information and establish the business&#39; overall security framework and sense of direction. It should also identify all security risks, how they will be managed, and the criteria needed to evaluate risks.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Has the organization implemented a risk assessment process?&lt;/span&gt;&lt;br /&gt;     A thorough risk assessment exercise must be conducted that takes into account the value and vulnerabilities of corporate IT assets, the internal processes and external threats that could exploit these vulnerabilities, and the probability of each threat. If a risk assessment methodology is in place, the standard recommends that organizations continue using this methodology.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: rgb(204, 0, 0); font-weight: bold;&quot;&gt;      Is a controls&#39; list available?&lt;/span&gt;&lt;br /&gt;     Necessary controls should be identified based on risk assessment information and the organization&#39;s overall approach for mitigating risk. Selected controls should then be mapped to Annex A of the standard — which identifies 133 controls divided in 11 domains — to complete a statement of applicability (SOA) form. A full review of Annex A acts as a monitoring mechanism to identify whether any control areas have been missed in the compliance planning process.&lt;br /&gt;  &lt;br /&gt;&lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;      Are security procedures documented and implemented?&lt;/span&gt;&lt;br /&gt;     Steps must be taken to maintain a structured set of documents detailing all IT security procedures, which must be documented and monitored to ensure they are implemented according to established security policies.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Is there a business continuity (BC) management process in place?&lt;/span&gt;&lt;br /&gt;     A management process must be in place that defines the company&#39;s overall BC framework. A detailed business impact analysis based on the BC plan should be drafted and tested and updated periodically.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Has the company implemented a security awareness program?&lt;/span&gt;&lt;br /&gt;     Planning and documentation efforts should be accompanied by a proper IT security awareness program so that all employees receive training on information security requirements.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;color: rgb(204, 0, 0); font-weight: bold;&quot;&gt;Was an internal audit conducted?&lt;/span&gt;&lt;br /&gt;     An internal audit must be conducted to ensure compliance with the standard and adherence to the organization’s security policies and procedures.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Was a gap analysis conducted?&lt;/span&gt;&lt;br /&gt;     Another important parameter to determine is the organization&#39;s level of compliance with the 133 controls in the standard. A gap analysis helps organizations link appropriate controls with the relevant business unit and can take place during any stage of the compliance process. Many organizations conduct the gap analysis at the beginning of the compliance process to determine the company&#39;s maturity level.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Were corrective and preventive actions identified and implemented?&lt;/span&gt;&lt;br /&gt;     The standard adheres to the Plan-Do-Check-Act&quot; (PDCA) cycle (PDF, 62KB) to help the organization know how far and how well it has progressed along this cycle. This directly influences the time and cost estimates to achieve compliance. To complete the PDCA cycle, the gaps identified in the internal audit must be addressed by identifying the corrective and preventive controls needed and the company&#39;s compliance based on the gap analysis.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Are there mechanisms in place to measure control effectiveness?&lt;/span&gt;&lt;br /&gt;     Measuring control effectiveness is one of the latest changes to the standard. According to ISO 27001, organizations must institute metrics to measure the effectiveness of the controls and produce comparable and reproducible results.&lt;br /&gt;  &lt;br /&gt;     &lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Is there a management review of the risk assessment and risk treatment plans?&lt;/span&gt;&lt;br /&gt;     Risk assessments and risk treatment plans must be reviewed at planned intervals at least annually as part of the organization&#39;s ISMS management review.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold; color: rgb(204, 0, 0);&quot;&gt;Analyze Return on Investment&lt;/span&gt;&lt;br /&gt;Based on the groundwork done so far, companies should be able to arrive at approximate time and cost estimates to implement the standard for each of the scope options. Organizations need to keep in mind that the longer it takes to get certified, the greater the consulting costs or internal staff effort. For example, implementation costs become even more critical when implementation is driven by market or customer requirements. Therefore, the longer compliance takes, the longer the organization will have to wait to reach the market with a successful certification.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;MOVING FORWARD&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Implementing ISO 27001 requires careful thought, planning, and coordination to ensure a smooth control adoption. The decision of when and how to implement the standard may be influenced by a number of factors, including different business objectives, existing levels of IT maturity and compliance efforts, user acceptability and awareness, customer requirements or contractual obligations, and the ability of the organization to adapt to change and adhere to internal processes.&lt;br /&gt;&lt;br /&gt;To learn more about the standard, BSI has prepared a guidance document available on its Web site, http://asia.bsi-global.com/InformationSecurity/ISO27001+Guidance/download.xalter. In addition, the Standards Direct Web site, www.standardsdirect.org/iso27001.htm, covers the latest version of the standard.&lt;br /&gt;&lt;br /&gt;K. K. Mookhey is the founder and principal consultant of Network Intelligence India (NII) Pvt. Ltd., an IT security consulting firm located in Mumbai, India, that offers ethical hacking, security auditing, BS 7799, and business continuity management services. Mookhey has worked on research projects for ISACA and has published several articles and white papers. He also has led teams on numerous security audit and implementation assignments and has trained people from the Big Four accounting firms and Fortune 500 companies on IT security issues.&lt;br /&gt;Khushbu Jithra has been part of all information security documentation projects for NII and helps to conduct security research for the organization. In addition, she drafts and reviews commercial proposals and security consulting reports, especially those dealing with penetration testing, vulnerability assessment, ISO 27001, and security audits.</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/7711489612227273150/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/7711489612227273150' title='31 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/7711489612227273150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/7711489612227273150'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2009/01/key-strategies-for-implementing-iso.html' title='Key Strategies for Implementing ISO 27001'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>31</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-3744826523969050803</id><published>2009-01-12T05:53:00.000-05:00</published><updated>2009-01-12T05:55:21.835-05:00</updated><title type='text'>Nhava Sheva becomes India&#39;s first security certified terminal</title><content type='html'>DUBAI: Global marine terminal operator DP World&#39;s Nhava Sheva International Container Terminal(NSICT) in India,has become the country&#39;s first to&lt;br /&gt;achieve ISO 28000:2007 certification in supply chain security management systems.&lt;br /&gt;&lt;br /&gt;With the certification announced yesterday, the terminal also known as DP World Nhava Sheva has become the 15th among the giant operator&#39;s network of 48 terminals worldwide, to get the distinction.&lt;br /&gt;&lt;br /&gt;The Certification, undertaken by independent Rotterdam-based Dutch auditing firm and Maritime Classification Society of excellence Det Norske Veritas(DNV), validates the NSICT&#39;s mechanisms and processes to address security vulnerabilities at strategic and operational levels, as well as its preparedness for preventive action plans.&lt;br /&gt;&lt;br /&gt;The Nava Sheva terminal, which boast of state-of-the art infrastructure and world class services, is already certified for ISO 9001, ISO 14001, OHSAS 18001 and ISO 27001 management systems.&lt;br /&gt;&lt;br /&gt;The terminal, was granted the certification after a thorough security audit of the facility, focused principally on container security, physical access controls, personnel security, procedural security, security training and threat awareness, business partner requirements and IT Security.&lt;br /&gt;&lt;br /&gt;&quot;Having an internationally recognised and certified security management system will greatly benefit DP World&#39;s customers and other terminal users and stakeholders who can now be assured that robust systems are in place to provide for the safety of their cargo and people using the terminal facilities in DP World Nhava Sheva,&quot; DP World Nhava Sheva&#39;s CEO, Capt Rustom Dastoor, said.&lt;br /&gt;&lt;br /&gt;Its investment in the ISO security management system has been recognised by the US Customs Border Protection agency, which invited DP World to join its Customs Trade Partnership Against Terrorism (C-TPAT) programme. &lt;br /&gt;&lt;br /&gt;Source: http://economictimes.indiatimes.com/</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/3744826523969050803/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/3744826523969050803' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/3744826523969050803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/3744826523969050803'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2009/01/nhava-sheva-becomes-indias-first.html' title='Nhava Sheva becomes India&#39;s first security certified terminal'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-2850276652497308791</id><published>2009-01-04T05:55:00.000-05:00</published><updated>2009-01-12T05:57:03.422-05:00</updated><title type='text'>VanceInfo Achieves ISO 27001 Security Certification</title><content type='html'>BEIJING, Dec. 15 /PRNewswire-Asia/ -- VanceInfo Technologies Inc. (&quot;VanceInfo&quot; or the &quot;Company&quot;), an IT service provider and one of the leading offshore software development companies in China, today announced that it has achieved the International Organization for Standardization (&quot;ISO&quot;) 27001 certification for Shanghai VanceInfo Technologies Limited (&quot;Shanghai VanceInfo&quot;), one of the Company&#39;s major subsidiaries.&lt;br /&gt;&lt;br /&gt;ISO creates standards that specify worldwide requirements for products, services, processes, materials and systems. ISO 27001 is the international standard developed specifically for Information Security Management Systems (&quot;ISMS&quot;), requiring that a company uses a systematic approach to managing sensitive corporate information and ensuring data security. VanceInfo&#39;s recent certification recognizes the Company&#39;s adoption of an effective information security system that complies with one of the highest established international standards.&lt;br /&gt;&lt;br /&gt;&quot;The protection of customers&#39; information, particularly intellectual property and trade secrets, is a top priority for VanceInfo. We strive to safeguard the integrity, availability and confidentiality of the data of our clients and business partners,&quot; said David Chen, President of VanceInfo, &quot;As one of the leading providers of offshore software development, VanceInfo has a longstanding commitment to applying best practices and technologies to software development for our clients. Achieving the ISO 27001 certification today and the CMMI Level 5 certification a quarter ago serves as confirmation that VanceInfo has made continuous efforts to meet the industry&#39;s most stringent standards.&quot;&lt;br /&gt;&lt;br /&gt;The ISO 27001 certification was awarded after detailed assessment of information security management in Shanghai VanceInfo&#39;s processes of software architect, development and testing. This accreditation marks another major step of VanceInfo toward achieving operational excellence and maximizing customer trust and confidence in the Company&#39;s IT infrastructure and security capabilities. The ISO 27001 certification will position VanceInfo with enhanced strengths in foreign markets where ISO standards provide uniformity across national and regional boundaries.&lt;br /&gt;&lt;br /&gt;About VanceInfo&lt;br /&gt;&lt;br /&gt;VanceInfo Technologies Inc. is an IT service provider and one of the leading offshore software development companies in China. VanceInfo was the first China software development outsourcer listed on the New York Stock Exchange.&lt;br /&gt;&lt;br /&gt;The Company ranked number one among Chinese offshore software development service providers for the North American and European markets as measured by 2007 revenues, according to International Data Corporation, or IDC, a leading independent market research firm.&lt;br /&gt;&lt;br /&gt;VanceInfo&#39;s comprehensive range of IT services includes research &amp; development services, enterprise solutions, application development &amp; maintenance, quality assurance &amp; testing, and globalization &amp; localization. VanceInfo provides these services primarily to corporations headquartered in the United States, Europe, Japan, and China, targeting high growth industries such as technology, telecommunications, financial services, manufacturing, retail and distribution.&lt;br /&gt;&lt;br /&gt;Safe Harbor&lt;br /&gt;&lt;br /&gt;This press release includes statements that may constitute forward-looking statements made pursuant to the safe harbor provisions of the U.S. Private Securities Litigation Reform Act of 1995. These forward-looking statements can be identified by terminology such as will, should, expects, anticipates, future, intends, plans, believes, estimates, and similar statements. Such statements are subject to risks and uncertainties that could cause actual results to differ materially from those projected. Further information regarding these and other risks is included in VanceInfo&#39;s filings with the U.S. Securities and Exchange Commission, including its registration statement on Form F-1. All information provided in this press release and in the attachments is as of December 15, 2008, and VanceInfo does not undertake any obligation to update any forward-looking statement as a result of new information, future events or otherwise, except as required under applicable law.&lt;br /&gt;&lt;br /&gt;Source: http://findarticles.com/</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/2850276652497308791/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/2850276652497308791' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/2850276652497308791'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/2850276652497308791'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2009/01/vanceinfo-achieves-iso-27001-security.html' title='VanceInfo Achieves ISO 27001 Security Certification'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-4194568888385573551</id><published>2008-12-23T08:52:00.003-05:00</published><updated>2008-12-23T10:48:29.712-05:00</updated><title type='text'>What It Means To Be ISO 27001 Certified - Benefits and Potential Payoffs</title><content type='html'>Mark Bernard is the Security &amp; Privacy Officer at Credit Union Central of British Columbia. Today, Mark&#39;s credit union is the first financial institution to achieve ISO 27001 certification. Mark discusses ISO 27001 certification and its benefits with BankInfoSecurity.com.&lt;br /&gt;&lt;br /&gt;Background: ISO 27001 is an information security management system (ISMS) standard published in October 2005 by the International Organization for Standardization (ISO). The certification ensures that effective security controls and policies are in place. The certification process is a measurement of the performance of best security practices and identification of opportunities to improve those practices. It basically involves testing the existence and effectiveness of the information security controls at any given institution.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight:bold;&quot;&gt;Benefits/ Payoffs of ISO 27001 Certification&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The Credit Union Central of British Columbia has changed remarkably in its level of security awareness, and the credit union system has gone up substantially. People now recognize the value of, or they are realizing the value of having an information security credential such as this, and it is helping the institution to identify information security issues and address them more effectively.&lt;br /&gt;&lt;br /&gt;As an institution in general, the culture has benefited as well. It&#39;s more focused on information security now and the identification of assets and how the credit union treats assets, threats, risk, and the vulnerability associated to those assets have been very positive.&lt;br /&gt;&lt;br /&gt;Such involvement also boosts the team culture that remains, and this team effort can be effectively channelized into other business areas.&lt;br /&gt;&lt;br /&gt;The ISO framework provides many of opportunities for improvement and to draw new sets of controls and to manage those more effectively likely than they have been in the past. Also, because the ISO framework already exists the credit union is looking at other standards such as the BS 25999, which is Business Continuity Standard, and integrating those controls within the ISMS.&lt;br /&gt;&lt;br /&gt;Becoming ISO certified also made a big difference to the institution economically by reducing the number of external consulting engagements that were necessary, costing hundreds of thousands of dollars. And now the credit union has a bonafide external audit group that comes by twice a year to monitor their activity and provide a list of opportunities for improvement.</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/4194568888385573551/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/4194568888385573551' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4194568888385573551'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4194568888385573551'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/12/what-it-means-to-be-iso-27001-certified.html' title='What It Means To Be ISO 27001 Certified - Benefits and Potential Payoffs'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-1228314189492243349</id><published>2008-12-18T14:04:00.000-05:00</published><updated>2008-12-18T14:06:42.765-05:00</updated><title type='text'>Promoting accountability through ISO/IEC 27001 &amp; 27002</title><content type='html'>As organisations go, there are those that welcome internationally recognised standards with open arms, and those that shy away citing cost or even applicability.&lt;br /&gt;&lt;br /&gt;However, there is a need for standards within all organisations, regardless of size or market. It is in defining the Statements of Applicability (SoA) that the project becomes both relevant and cost-effective.&lt;br /&gt;&lt;br /&gt;There is &quot;information&quot; within every organisation that is relied upon, so a system is required to manage its security. At the least, we need to ensure that the information is viable for its purpose.&lt;br /&gt;&lt;br /&gt;Combined, these provide best practice guidance and a framework for an information security management system (ISMS) - ISO/IEC 27001 - and the management thereof - ISO/IEC 27002 - for the protection, confidentiality, integrity and availability of the information assets upon which an organisation depends.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight:bold;&quot;&gt;Code of practice&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;ISO/IEC 27002 is merely a code of practice, so organisations are free to implement controls as they see fit, and the ISO/IEC 27001 standard incorporates only a simple summary of such controls and does not mandate any.&lt;br /&gt;&lt;br /&gt;An important element is the definition of the SoA, among other scoping documents.&lt;br /&gt;&lt;br /&gt;Through the SoA you are free to broaden or narrow the scope of certification, as you see fit, limiting the focus of any analysis. Understanding the SoA is crucial to attaching meaning to the certificate.&lt;br /&gt;&lt;br /&gt;If you only define &quot;the HR department&quot;, the associated certificate says nothing about the state of information security in &quot;procurement&quot;, &quot;manufacturing&quot;, &quot;the IT department&quot; or even the organisation as a whole. You set the scope.&lt;br /&gt;&lt;br /&gt;Similarly, if the SoA asserts that some technical controls are not necessary for specified reasons, the assessing body will check that assertion but will not otherwise certify or fail those controls or the lack of them. In fact, no technical controls may be assessed at all as part of the assessment as ISO/IEC 27001 is primarily a management standard and compliance requires only that the organisation has a suite of management controls in place. If you feel a control is not necessary, giving a valid reason should suffice.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight:bold;&quot;&gt;Start small&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Look towards the information assets you currently manage or those you feel you can easily manage within the reduced scope, define a narrow SoA focused on what is already known and document your process to define, design, implement and manage these controls, including those &quot;few&quot; controls that may be missing.&lt;br /&gt;&lt;br /&gt;Beyond certification or having marketing potential the process of assessment should confirm or improve accountability internally for information asset interfaces with wider business functions and third parties, confirming the scope for use of information assets with those partners.&lt;br /&gt;&lt;br /&gt;Certification is optional, but is increasingly being mandated from suppliers and business partners concerned about their information security and the security of shared or common information.&lt;br /&gt;&lt;br /&gt;Bodies such as the British Standards Institution, the National Institute of Science and Technology and various national bodies are issuing approximately 1,000 certificates per year - and the trend is growing.&lt;br /&gt;&lt;br /&gt;By concentrating on the known information assets of a small business function, defining your ISMS to manage these will get you on the ladder and act as a springboard to widen your certification later.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight:bold;&quot;&gt;ISO/IEC 27001 &lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;ISO/IEC 27001 is a formal standard towards which your organisation can attain independent certification of its frameworks to systematically and consistently design, implement, manage, maintain and enforce information security processes and controls - an information security management system (ISMS).&lt;br /&gt;&lt;br /&gt;It covers any organisation (commercial business, government body or non-profit organisation), specifying the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a well-documented ISMS, within the context of the organisation&#39;s overall risk management processes.&lt;br /&gt;&lt;br /&gt;It defines the requirements for custom security controls that meet the specific needs of the organisation or, importantly, any specified part or department thereof.&lt;br /&gt;&lt;br /&gt;Source: http://www.computerweekly.com&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-style:italic;&quot;&gt;David Gregg is an infrastructure and security consultant at The Logic Group&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/1228314189492243349/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/1228314189492243349' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/1228314189492243349'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/1228314189492243349'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/12/promoting-accountability-through-isoiec.html' title='Promoting accountability through ISO/IEC 27001 &amp; 27002'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-959124931349788388</id><published>2008-12-18T14:00:00.001-05:00</published><updated>2008-12-18T14:03:21.134-05:00</updated><title type='text'>The growing accreditation of IT security tools and processes</title><content type='html'>Vincent Villers, Partner at PwC Luxembourg and Marc Sel, Director at PwC Belgium&lt;br /&gt;Business review, December 2008&lt;br /&gt;&lt;br /&gt;For a long time, Information Security has had many technical standards but has been lacking a minimal consensus in the area of management and responsibilities. The BSI (British Standards Institute) put forward their 7799 standards, which were well accepted and evolved into the ISO (International Standards Organisation) world. Fundamental to the ISMS (Information Security Management System) standard is the typical management organisation model ‘Plan-Do-Check-Act’:&lt;br /&gt;&lt;br /&gt;&lt;a onblur=&quot;try {parent.deselectBloggerImageGracefully();} catch(e) {}&quot; href=&quot;http://www.pwc.com/extweb/ncpressrelease.nsf/42e3ba9660db98bc80257148004ee49a/cefef1398ae629ce802575210031be2f/Body/71.4962?OpenElement&amp;FieldElemFormat=gif&quot;&gt;&lt;img style=&quot;display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 498px; height: 269px;&quot; src=&quot;http://www.pwc.com/extweb/ncpressrelease.nsf/42e3ba9660db98bc80257148004ee49a/cefef1398ae629ce802575210031be2f/Body/71.4962?OpenElement&amp;FieldElemFormat=gif&quot; border=&quot;0&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ISO 27001 is commonly used as a term to refer to a family of interrelated standards:&lt;br /&gt;&lt;br /&gt;• 27000 ISMS fundamentals and vocabulary&lt;br /&gt;• 27001 ISMS requirements (absorbing parts of ISO 13335)&lt;br /&gt;• 27002 Code of practice (based on the BSI 7799)&lt;br /&gt;• 27003 ISMS implementation guidelines&lt;br /&gt;• 27004 Information security management measurements&lt;br /&gt;• 27005 ISMS risk management (absorbing parts of ISO 13335)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight:bold;&quot;&gt;Structure of ISO 27001&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The main standard document ISO 27001 addresses requirements for the Information Security Management System, as well as how to establish, manage and monitor the ISMS. It continues by addressing ISMS responsibilities, as well as audit and management review aspects.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight:bold;&quot;&gt;The ISO 27001 certification process&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In many countries, certification bodies have been established under the umbrella of accreditation bodies. For example, one of the authors, Marc Sel, is accredited Lead Auditor for PwC’s Certification Body ‘PwCC B.V.’ which is on a peer level with the BSI, TÜV and KEMA1 . PwCC B.V. is in turn accredited by the Dutch Accreditation Body (‘Raad voor Accreditatie’).&lt;br /&gt;&lt;br /&gt;The International Register of ISMS accredited certificates lists those certificates that have been awarded to organisations that have gone through an accredited certification process in line with the ISMS standard BS 7799 Part 2:2002 and ISO/IEC 27001:2005 (i.e. the revised version of BS 7799 Part 2:2002).&lt;br /&gt;&lt;br /&gt;This register has been produced in cooperation with the international network of certification bodies and is managed and maintained by the ISMS International User Group (IUG). It is updated on a regular basis in co-operation with the certification bodies. The entries in this register have been supplied by those certification bodies that have carried out the ISMS certification.&lt;br /&gt;&lt;br /&gt;The increasing interest in ISO 27001 certification&lt;br /&gt;&lt;br /&gt;In November 2008, almost 5.000 ISMS certificates have been issued (4.987 to be precise2) . The top five countries with the highest number of certificates today are Japan, India, the UK, Taiwan and China. They are followed by Germany and the USA.&lt;br /&gt;&lt;br /&gt;The best advice to follow is to centralise core IT services in larger data centres. For example, the data centres of PwC Yemen, UK, Hong Kong, China, and USA have been secured by ourselves and accredited by the BSI against ISO 27001:2005. This gives us a strong background when helping customers prepare for such certification or improve their security posture.&lt;br /&gt;&lt;br /&gt;In Luxembourg, only one company is registered as being accredited against the standard so far. However, considering the current trend of financial institutions to focus on their core business by considering outsourcing of several functions, coupled with the increasing need to embed trust in business relationship, all conditions are fulfilled to lead to a growing interest for this certification. Indeed, unlike current perception of other standards, the ISO 27001:2005 relies upon clear requirements and implementation guidelines that provides sufficient transparency to bring the required level comfort that an accredited company meets adequate level of security to build trust with its stakeholders. The implementation of an ISO 27001 ISMS is clearly becoming an optimal approach to help organisations tackle the current regulatory requirements with regards to Information Technology controls.&lt;br /&gt;&lt;br /&gt;Finally, rather than individually answering each request for compliance, it is advised to look at the requirements holistically, and build a framework that allows demonstrating compliance against a broad set of regulations, re-using the same set of well-defined controls. The implementation of such a control framework makes demonstrating compliance significantly less expensive.&lt;br /&gt;&lt;br /&gt;1 BSI British Standards is the National Standards Body of the UK, TÜV Rheinland Group is a leading provider of technical services worldwide, KEMA is a commercial enterprise, specializing in high-grade business and technical consultancy, inspections and measurement, testing and certification.&lt;br /&gt;2 The status of the official ISO 27001 certificates is available at www.iso27001certificates.com&lt;br /&gt;&lt;br /&gt;Source: PwC</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/959124931349788388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/959124931349788388' title='31 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/959124931349788388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/959124931349788388'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/12/growing-accreditation-of-it-security.html' title='The growing accreditation of IT security tools and processes'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>31</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-1825799599305086842</id><published>2008-12-15T14:08:00.000-05:00</published><updated>2008-12-18T14:09:06.019-05:00</updated><title type='text'>VanceInfo Technologies gets ISO 27001 certification for Shanghai VanceInfo Technologies</title><content type='html'>VanceInfo Technologies Inc. (VIT:  News ) Monday said it achieved the International Organization for Standardization 27001 certification for its subsidiary Shanghai VanceInfo Technologies Limited. VanceInfo&#39;s recent certification recognizes the company&#39;s adoption of an effective information security system that complies with one of the highest established international standards.&lt;br /&gt;&lt;br /&gt;VanceInfo Technologies Inc. is an IT service provider and an offshore software development company in China.</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/1825799599305086842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/1825799599305086842' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/1825799599305086842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/1825799599305086842'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/12/vanceinfo-technologies-gets-iso-27001.html' title='VanceInfo Technologies gets ISO 27001 certification for Shanghai VanceInfo Technologies'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-3490682580611558239</id><published>2008-12-09T06:59:00.000-05:00</published><updated>2008-12-09T07:00:04.140-05:00</updated><title type='text'>Gary Hinson on ISO/IEC 27000</title><content type='html'>Few doubt that a major consequence of the current economic meltdown will be more regulations for the private sector to follow. New regulations almost always mean more spending on security and privacy controls. For a glimpse of what to expect, CSO turned to Gary Hinson, a New Zealand-based IT governance specialist and CEO of IsecT Ltd.&lt;br /&gt;&lt;br /&gt;Hinson says to expect changes in the coming year, but they won&#39;t necessarily be tied to new regulations born of the financial crisis. Instead, his focus is on changes for the ISO/IEC 27000 family of standards. His efforts to help security pros understand the standards include a regularly-updated website: ISO27001security.com. Hinson spoke with CSOonline.com Senior Editor Bill Brenner about the nature and timing of updates to these important standards.&lt;br /&gt;&lt;br /&gt;Where do you see the most significant regulatory changes in 2009?&lt;br /&gt;There are a number of planned changes to the ISO/IEC 27000 family of Information Security Management System (ISMS) standards (collectively &quot;ISO27k&quot;) over the next year or so, with several additional standards currently under development, several standards about to be released and earlier releases undergoing planned revision.&lt;br /&gt;&lt;br /&gt;Let&#39;s start with the planned revisions.&lt;br /&gt;Work is under way within JTC1/SC27, the ISO/IEC committee responsible for ISO27k, to review and where necessary adapt ISO/IEC 27001 and 27002. Both standards are being actively used around the world of course, making it likely that changes will be relatively limited in order to avoid disrupting the existing implementations and particularly the certification processes. I believe that in Japan, for instance, ISO/IEC 27002 is specifically recommended if not required to satisfy the Japanese privacy/data protection laws, with organizations being compliance-assessed against the code of practice although it was not originally intended by ISO/IEC to be used in that manner. No one really knows how many organizations have adopted ISO/IEC 27002 globally but I would guess it must be in the hundreds of thousands by now.&lt;br /&gt;&lt;br /&gt;In revising ISO/IEC 27002, what are you pressing the committee to focus on?&lt;br /&gt;&lt;br /&gt;   1. Address and resolve the confusion around &quot;information security policy&quot; versus &quot;ISMS policy&quot; -- the latter being closer to strategy, as far as I can see.&lt;br /&gt;   2. Expand on the concept of personal accountability versus responsibility and clarify what is meant by &quot;information asset.&quot;&lt;br /&gt;   3. Expand on typical computer room controls, for example environmental monitoring with local and remote alarms for fire, water, intrusion, power problems etc.&lt;br /&gt;   4. Update section 10.8 &quot;Exchange of information&quot; to improve coverage of mobile code, Web 2.0/Software As A Service etc. Technical advances are a tricky area for ISO27k since publication of the standards is such a long, slow process They try as far as possible to keep the standards technology-neutral but this can result in them lacking guidance in some areas].&lt;br /&gt;   5. Expand section 11.2 on &quot;User access management&quot; to include more on identification and especially authentication of remote users.&lt;br /&gt;   6. Provide pragmatic guidance on security testing of new/changed application systems in section 12.&lt;br /&gt;   7. Expand section 14 on &quot;Business continuity management&quot; to cover resilience as well as disaster recovery. This section would also benefit from more explanation of &quot;contingency.&quot;&lt;br /&gt;   8. Update section 15 to reflect legal and regulatory changes such as the rise of e-discovery, document/e-mail retention and increasing use of computer data as evidence in court.&lt;br /&gt;   9. Emphasize the value of IT auditing processes in section 15.3. &lt;br /&gt;&lt;br /&gt;Source: CSO Online</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/3490682580611558239/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/3490682580611558239' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/3490682580611558239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/3490682580611558239'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/12/gary-hinson-on-isoiec-27000.html' title='Gary Hinson on ISO/IEC 27000'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-871840445486339654</id><published>2008-11-13T11:33:00.000-05:00</published><updated>2008-11-13T11:41:06.305-05:00</updated><title type='text'>Emloyee education key to successful enterprise security</title><content type='html'>Money can buy you many things, it seems, but not perfect security. Organisations have been investing in IT security over the past few years, but laptops and disks full of sensitive data are still going missing and corporate networks are still being hacked.&lt;br /&gt;&lt;br /&gt;In all these breaches, the common link has become increasingly obvious: employees. Whether they are failing to abide by corporate policies, simply don&#39;t know about them, or work in a company that has no security policies in place, staff are mailing out millions of user accounts without proper encryption, giving out passwords over the phone and double-clicking on attachments that promise naughty pictures of Angelina Jolie.&lt;br /&gt;&lt;br /&gt;A recent survey of 1,000 IT managers by mobile data security specialist SafeBoot showed that 54 per cent of respondents felt that the majority of their employees ignore company security policies, mainly due to a lack of understanding and &quot;not taking it seriously&quot;.&lt;br /&gt;&lt;br /&gt;The answer then should be clear: educate employees about the risks and what they should be doing to reduce them. And indeed, some companies are already doing that. But SafeBoot&#39;s research shows that 98 per cent of IT managers rely on memos and emails to communicate security. As Tom de Jongh, product manager at SafeBoot, points out: &quot;You can&#39;t trust employees to read memos.&quot;&lt;br /&gt;&lt;br /&gt;So what is the best way to teach employees about security - and get them to follow the advice? The first step is to realise that not everything is going to happen overnight. &quot;You need to change the culture of the organisation over several years,&quot; says Martin Smith, chairman and founder of The Security Company. Smith, who started his career in military counter-intelligence and counter-espionage, has been trying to convince businesses of the importance of security awareness for 20 years.&lt;br /&gt;&lt;br /&gt;&quot;It&#39;s heartbreaking,&quot; he laments. &quot;Infosec is focusing frantically on technology, but it doesn&#39;t matter what you spend on security unless you bring people with you. If staff could just know some basic stuff, it would all go away.&quot;&lt;br /&gt;&lt;br /&gt;Generating this culture of security is an important component of overall security awareness. &quot;There&#39;s an awful lot that users need to know - too much,&quot; Smith adds. &quot;They&#39;re overloaded with information they&#39;re not really interested in - it&#39;s boring.&quot; Rather than trying to teach people using courses, he advises to have constant reinforcements of messages about the importance of security in conjunction with a place for employees to find out information.&lt;br /&gt;&lt;br /&gt;Bad awareness education can be even worse than no training at all, Smith suggests. &quot;Employees will always ask: &#39;What&#39;s in it for me?&#39;. If all people see of security is a boring course once a year that effectively pushes the problem on to them so that the security team&#39;s arse isn&#39;t on the line, that&#39;s not a huge sell.&quot; Measures such as providing somewhere for employees to find out security information, letting them know that breaches in security could cost the company severely, creating a culture of security and not forcing them to do anything, are far more likely to make employees security aware.&lt;br /&gt;&lt;br /&gt;Assuming the constant reinforcement of the message is getting through, employees who are about to perform an action that might be potentially dangerous will pause to think and consult the knowledge zone for the correct procedure. &quot;Then you&#39;ll have employees thinking: &#39;Send out 25 million bits of information? That doesn&#39;t sound right. I&#39;ll just check the knowledge zone,&#39;&quot; Smith says.&lt;br /&gt;&lt;br /&gt;Obviously, creating an intranet knowledge zone or having a security support team to answer queries takes resources. Cliff May, consulting manager at Integralis, often has to teach employees of client organisations about security as part of ISO27001 audits. He uses seminars and e-learning packages to educate users, but prefers seminars. &quot;E-learning is not as effective. If you run tests, sometimes people get the answers off someone else - it&#39;s a paper exercise they just want to get over with.&quot;&lt;br /&gt;&lt;br /&gt;Nevertheless, they can work well if you&#39;re prepared to invest in them properly. Paul King is a member of Cisco&#39;s security programmes organisation, which runs training around the world. As well as an initial induction programme that uses face-to-face training, Cisco uses e-learning systems featuring specially shot videos put together by professional video makers. &quot;We keep them quite short, simple and interesting. There are also questions interspersed throughout, although they&#39;re not as hard as an exam.&quot;&lt;br /&gt;&lt;br /&gt;Cisco has an internal home page with links to take people through to the e-training videos. Using web analytics, the company monitors which employees have been watching videos. &quot;Everyone in the organisation understands that the need for security awareness comes down from John Chambers (Cisco&#39;s CEO).&quot; But if employees aren&#39;t watching the videos they&#39;re supposed to be watching, their line managers will be asked why.&lt;br /&gt;&lt;br /&gt;King says the company can also tell how effective training has been through other means. A recent video on &quot;shoulder surfing&quot; emphasised the importance of using privacy screens when working on laptops in public places. A link next to the video took the user to a place where they could buy a screen through their department&#39;s budget. &quot;Take-up was huge. Lots of people now have screens on their laptops. That&#39;s our measure.&quot;&lt;br /&gt;&lt;br /&gt;Cisco only produces a few of these videos. For the most part, it provides a constant background of security information to create a secure culture. It uses poster campaigns and newspapers among other things. A recent effort suggested employees should think of themselves as &quot;security champions&quot;, trying to keep the company safe.&lt;br /&gt;&lt;br /&gt;However, Robin Adams, head of the security division at the Logic Group, cautions against relying on posters. &quot;The feedback I get is that posters work for about a month.&quot; Similarly, signs to remind users of good behaviour tend to fade into the background within days.&lt;br /&gt;&lt;br /&gt;Although seminars can be expensive and not as effective in the long-term as other methods, they can work well in small companies. Firebrand offers low-level training courses that clear away jargon and acronyms - something that can creep in if security staff put on their own seminars without input from marketing, training or HR departments.&lt;br /&gt;&lt;br /&gt;David Cole, academy team leader and senior consultant at risk consultancy DNV, suggests that role-playing works well in workshops and seminars. &quot;There&#39;s a danger in infosec training that you end up showing slide after slide,&quot; he warns. &quot;But you need to make it fun. You can have training exercises and create a scenario that builds slowly over the day.&quot;&lt;br /&gt;&lt;br /&gt;May at Integralis uses anecdotes from his forensics career to enliven his sessions. &quot;You get senior people turning up because they hear it&#39;s interesting. If you can add a bit of humour, they can enjoy proceedings.&quot; He also advocates the use of role-playing: &quot;They have to think for themselves. It&#39;s a good way of making it sink in.&quot; Nevertheless, although he is in favour of induction courses, he considers a presentation by itself &quot;virtually worthless&quot;.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;It could be you&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Getting employees to pay attention to all these messages usually involves sticks and carrots. Annual exams can test how much has actually sunk in. Strong punishments for people who have knowingly broken security policies can set an example and demonstrate the company is serious about security. But the Logic Group&#39;s Adams says that, in his experience, painting a worst-case scenario of what could happen works &quot;amazingly well&quot; when it comes to convincing staff to abide by the policies anyway. &quot;If you explain that credit-card companies might take away their ability to process cards for orders, together with the effect that would have on jobs, people really listen.&quot; Explaining what information might be worth to criminals also helps, he adds.&lt;br /&gt;&lt;br /&gt;Ultimately, no matter how good security technology becomes, people will always be a weak link. Ignoring this fact is, as Smith suggests, like focusing on brain surgery when the patient is dying of the common cold.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;TOP TEN TIPS FOR YOUR STAFF&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;1. Make sure that all redundant equipment, documents and waste are removed as appropriate. It&#39;s no use protecting data on your PC if it&#39;s on your desk for everyone to see.&lt;br /&gt;&lt;br /&gt;2. Lock your workstations when left unattended and log off at the end of your working day.&lt;br /&gt;&lt;br /&gt;3. Don&#39;t share computer passwords except under the most exceptional emergency circumstances.&lt;br /&gt;&lt;br /&gt;4. Don&#39;t make your password easy to guess. It should be at least eight characters, different for each account and not based on personal things such as dates or pet names.&lt;br /&gt;&lt;br /&gt;5. Organised crime is at work and the average criminal is more motivated to steal from you than you are to defend yourself.&lt;br /&gt;&lt;br /&gt;6. If you have a laptop, don&#39;t leave it on display in your car. Get a laptop cable lock. Many thefts are crimes of opportunity.&lt;br /&gt;&lt;br /&gt;7. Avoid working in a public place, you never know who&#39;s watching. If you must, get a privacy protector.&lt;br /&gt;&lt;br /&gt;8. Do not connect devices such as iPods, USB drives or even CDs to your PC without checking with IT - these can all carry malicious software.&lt;br /&gt;&lt;br /&gt;9. Don&#39;t reveal details of your work security with anyone. If someone is trying to break in, they&#39;ll try to get as much information as possible.&lt;br /&gt;&lt;br /&gt;10. If you think something is suspicious, report it. Many crimes are successful because earlier, unsuccessful break-in attempts weren&#39;t spotted by the right people.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;CASE STUDY: RICOH&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Japanese digital office-solutions company Ricoh has nearly 82,000 employees and offices in more than 150 countries. Three years ago, the company decided to go for a single global certification for ISO27001.&lt;br /&gt;&lt;br /&gt;Kevin McLean, information security manager at Ricoh Europe, has been in charge of the EMEA aspects of the certification. &quot;In order to achieve the certification, we created a project team. The team worked with the IT, HR and facilities management departments to establish the information security management system (ISMS) with a focus on access control, from IT systems to buildings. Recruitment policies were reviewed to cover the management of contractors and permanent personnel.&quot;&lt;br /&gt;&lt;br /&gt;However, McLean knew that employee awareness would also be a vital part of both certification and the company&#39;s security policy. &quot;While we strive to be as strong as can be with physical security, it can all be undone by people,&quot; he says.&lt;br /&gt;&lt;br /&gt;So he and his team created a security awareness programme. They began with pilots in a number of offices, including the company&#39;s European HQ in London. They also set up ISMS business representatives groups, bridging units at each pilot area between their own division and the rest of the company, which met to decide activities and projects designed to improve employee awareness. &quot;We tried a number of things to see how they were received.&quot; Since the pilot project at the HQ was in a relatively small area, it was possible to take advantage of &quot;water cooler&quot; chat to discover how much of the message was getting through. Managers told them that more staff were wearing ID badges, clearing their desks at the end of the day and performing other actions they had been advised to perform.&lt;br /&gt;&lt;br /&gt;To get the message across, the unit devised initiatives including informal launches, articles on the intranet, a staff handbook and mandatory awareness training. Staff were also given free gifts, including a personal alarm and SIM card replicator, to reinforce the security message. A set of &quot;11 commandments&quot; based around the &quot;DOIT&quot; slogans (&#39;protecting documents, office and IT&#39;) further added to the message.&lt;br /&gt;&lt;br /&gt;&quot;HR and marketing helped come up with the slogans,&quot; recalls McLean. &quot;And HR were able to tap training and similar resources.&quot; Seminars and workshops involving role-playing allowed staff to explore security issues related to their working day. &quot;Employees weren&#39;t interested in big picture stuff. It was all about &#39;How does this affect me?&#39;&quot;&lt;br /&gt;&lt;br /&gt;Although Ricoh now has the certification, McLean says the programme will continue. &quot;We&#39;re always going to be improving it.&quot;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;WORKING WITH OTHER DEPARTMENTS&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If security is seen as an IT issue, it will be left to the IT department to sort it out. Apart from the crippling amounts of extra work, that will mean security being someone else&#39;s problem rather than an issue for the whole company. So it&#39;s important to get other departments to work in conjunction with IT to ensure that the security message gets through and is seen as everyone&#39;s concern.&lt;br /&gt;&lt;br /&gt;This usually involves board-level support as well as a &quot;bridging unit&quot; or a business relationship manager, depending on the size of the company, to liaise between IT and other departments. If you can get funding from those departments, they will be far more committed to the issue than if they are merely asked to give up their time.&lt;br /&gt;&lt;br /&gt;The HR and legal departments can be useful, as they can ensure that employee contracts include suitable rules about security and IT use, together with appropriate actions in case employees break them. This means that if someone does cause a security breach, the contract, together with the training given to them, significantly reduces the chance of a lawsuit for unfair dismissal being filed against the company. Liaising with HR means security training can be part of the induction programme, avoiding the problem of security being seen as something &quot;other&quot;.&lt;br /&gt;&lt;br /&gt;Marketing, training and other corporate communications departments have those vital people skills that some IT specialists lack. When creating awareness campaigns, marketing can help to devise the most effective methods of getting the message across. And while IT can certainly provide the information about security that needs to be given to employees, a training or HR department is far more likely to be able to deliver seminars and courses in a way that non-technical people will appreciate.&lt;br /&gt;&lt;br /&gt;Source: http://www.securecomputing.net.au/</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/871840445486339654/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/871840445486339654' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/871840445486339654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/871840445486339654'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/11/emloyee-education-key-to-successful.html' title='Emloyee education key to successful enterprise security'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-4485202600576962476</id><published>2008-11-11T11:44:00.000-05:00</published><updated>2008-11-13T11:46:37.830-05:00</updated><title type='text'>Security survey finds increase in security standards adoption</title><content type='html'>&lt;b&gt;News Analysis&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.ey.com/Global/assets.nsf/UK/Global_Information_Security_Survey_2008/$file/EY_Global_Information_Security_Survey_2008.pdf&quot;&gt;Ernst &amp;amp; Young&#39;s 2008 Global Information Security Survey&lt;/a&gt; begs the eternal question, depending on how you look at the numbers: Is the glass half full or half empty?&lt;br /&gt;&lt;br /&gt;For example, the survey clearly shows that many companies may be slow to address growing security concerns, such as reliance on third parties -- partners, vendors and contractors. Only 45% of respondents include specific security requirements in all third-party contracts, but an optimist might say this reflects a trend in the right direction. One wonders if the other 55% write language into their more sensitive contracts that involve sharing confidential data or access to key systems.&lt;br /&gt;&lt;br /&gt;The 11th annual survey by Ernst &amp;amp; Young (E&amp;amp;Y) polled nearly 1,400 organizations in more than 50 countries with annual revenues ranging from less than $100 million to more than $25 billion, as well as non-profits. Nearly a third of the organizations polled were in the financial services sector and 13% were in manufacturing, the second highest group.&lt;br /&gt;&lt;br /&gt;The report comes on the heels of PricewaterhouseCoopers&#39; annual Global State of Information Security Survey.&lt;br /&gt;&lt;br /&gt;On a positive note, adoption of international information security standards is clearly trending up. Use of ISO/IEC 27001:2005 was up 15% over 2007 and ISO/IEC 27002:2005 rose 9% over 2007. The E&amp;amp;Y report stated that management standards, such as ISO 9000, have been adopted in certain industries where information security standards are becoming a necessity for doing business.&lt;br /&gt;&lt;br /&gt;The survey also found that organizations are overwhelmingly planning to increase or maintain information security spending as a percentage of their total expenditures. The survey was conducted from June 6 to August 1, before the international economic crisis was in full bloom, so the question going forward is: What was the impact on total expenditures? It would be interesting to see the results if the survey was conducted now.&lt;br /&gt;&lt;br /&gt;Interestingly, 50% of the respondents said organizational awareness was the most significant challenge to information security initiatives, edging out availability of resources, budget and addressing new threats and vulnerabilities. While the survey didn&#39;t specifically address training or awareness programs, only 19% of the respondents said they ran social engineering tests, while Internet and infrastructure testing is also common practice at 85% and 73% respectively.&lt;br /&gt;&lt;br /&gt;While E&amp;amp;Y says regulatory compliance has been the leading driver for information security since 2005, it reports that protecting reputation and brand has become a significant driver as well. However, the question asked was not what drives information security initiatives and spending, but rather, what are the perceived consequences of security incidents? What is the &quot;level of significance if information is lost, compromised or unavailable&quot; Eighty-five percent of respondents said damage to reputation and brand was &quot;significant&quot; or &quot;very significant,&quot; followed closely by loss of stakeholder confidence, loss of revenue, regulatory action and legal action.&lt;br /&gt;&lt;br /&gt;Though the report cites compliance as a driver for raising security awareness and improvements, there&#39;s room for healthy skepticism about how much companies would do if they weren&#39;t compelled. Every car should have seatbelts, but how many had them before they were mandated?&lt;br /&gt;&lt;br /&gt;Other key findings:&lt;br /&gt;&lt;br /&gt;# Business continuity is an IT responsibility in 41% of the organizations, compared to 20% in risk management and 11% in information security. It would be interesting to see if this is trending toward or away from IT.&lt;br /&gt;&lt;br /&gt;# Most organizations are unwilling to outsource key information security activities. This is somewhat interpretive. While two-thirds to three-quarters of the respondents are keeping things like vulnerability and patch management, incident response, DR/BC, security awareness training and e-discovery and forensics in-house, the majority are either outsourcing or planning to outsource security assessments, audits and pen testing.&lt;br /&gt;&lt;br /&gt;# Few companies hedge information security risks with cyber insurance. Generally, around 10% of the organizations have some sort of insurance in one or more of eight information security-related areas, such as the cost of incident response or litigation, and few of the others have plans in the next 12 months. About one-third said they don&#39;t know, which leaves some potential for growth in the future.&lt;br /&gt;&lt;br /&gt;Source: http://searchsecurity.techtarget.com/</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/4485202600576962476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/4485202600576962476' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4485202600576962476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4485202600576962476'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/11/security-survey-finds-increase-in.html' title='Security survey finds increase in security standards adoption'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-4736658849284617647</id><published>2008-11-05T11:41:00.000-05:00</published><updated>2008-11-13T11:43:01.694-05:00</updated><title type='text'>Broadridge receives ISO 27001 certification for ProxyPlus</title><content type='html'>&lt;p&gt;This international certification specifically covers Broadridge&#39;s Information Security Management Systems (ISMS) for these flagship products, validating that the associated security policies for these applications have undergone in-depth testing and external audits. The new certification provides better protection and privacy for Broadridge&#39;s clients&#39; data by ensuring that there is enhanced tracking and reporting on the company&#39;s security initiatives. Broadridge is distinguished among its competitors for its superior information security model and is one of only 77 companies in the United States that are currently ISO 27001 certified; of these companies, less than 10% are in the financial services industry.&lt;/p&gt; &lt;p&gt;Broadridge recognizes that the data processed by Broadridge on behalf of its clients is among its clients&#39; most vital assets as it is confidential information related to their retail and institutional brokerage and investor communications activities. The certification adds yet another layer of security for Broadridge clients as they conduct their integral operations and transactions using key Broadridge applications to process this data. ProxyPlus is Broadridge&#39;s enterprise application that supports the core processing functions of Broadridge&#39;s proxy services, the company&#39;s largest business. Broadridge&#39;s BPS platform is one of the most robust securities processing engines in the industry for equities, mutual funds, and options providing real-time interfaces, as well as links to all major United States exchanges. Broadridge&#39;s impact solution is an integrated, online fixed-income securities transaction processing system, offering leading global financial institutions the ability to process fixed-income trades from order entry through to customized post-trade reporting. The certification of ProxyPlus, BPS, and impact offers the global banks and broker-dealers as well as corporate issuers and mutual funds whose data is processed using these three applicatiications, the assurance that Broadridge has created and implemented information security practices that are comprehensive and stringent enough to meet ISO standards.&lt;/p&gt; &lt;p&gt;The ISO 27001 Certification is designed to assist corporations with the development of a consistent methodology for implementing information security at the program level, as well as defining key control objectives designed to protect information assets. ISO 27001 is the only auditable international standard which defines the requirements to ensure that sufficient security controls are instituted within the certified organization. Additionally, maintaining the ISO 27001 Certification requires an annual review and three year re-certification. The continual scrutiny of Broadridge&#39;s ISMS in this manner provides confidence to clients that their data is protected on an ongoing basis.&lt;br /&gt;&lt;br /&gt;&quot;We are proud to have earned this certification and believe it reflects the dedication of our Information Security team to ensure that we have the highest level of controls in place when handling our clients&#39; confidential information,&quot; said Mark Schlesinger, Chief Information Officer, Broadridge. &quot;Data security is essential to the survival and stability of any organization and Broadridge&#39;s ISO Certification offers our clients a higher level of safeguard and protection for their information assets,&quot; Mr. Schlesinger added. To ensure that management is closely tied to ISO 27001 compliance, Broadridge has created a governance program that includes a management committee and has appointed information security champions in departments and divisions throughout the company whose job it is to support ongoing and timely security enhancements. This certification is just the beginning of what is envisioned as a multi-year plan to enhance and expand Broadridge&#39;s internal controls and security strategy.&lt;/p&gt;&lt;p&gt;Source: http://www.finextra.com&lt;br /&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/4736658849284617647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/4736658849284617647' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4736658849284617647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4736658849284617647'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/11/broadridge-receives-iso-27001.html' title='Broadridge receives ISO 27001 certification for ProxyPlus'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-4459385231638948200</id><published>2008-11-01T11:30:00.000-04:00</published><updated>2008-11-13T11:33:11.936-05:00</updated><title type='text'>UK – Paternoster plans to achieve data protection compliance</title><content type='html'>Paternoster has said it plans to be the first insurer to be certified for the data protection standard ISO 27001 following its Indian operations being passed as ISO 27001-complaint in June this year.&lt;br /&gt;&lt;br /&gt;The certification process ensures the company adheres to the tight data security standards demanded by the global standard.&lt;br /&gt;&lt;br /&gt;Source: http://globalpensions.com/</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/4459385231638948200/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/4459385231638948200' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4459385231638948200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4459385231638948200'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/11/uk-paternoster-plans-to-achieve-data.html' title='UK – Paternoster plans to achieve data protection compliance'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-1917137918339579367</id><published>2008-10-21T11:24:00.000-04:00</published><updated>2008-11-13T11:28:46.769-05:00</updated><title type='text'>BTA Bank pioneered information Security Management System in Kazakhstan</title><content type='html'>The FINANCIAL -- BTA Bank JSC is a sole bank in Kazakhstan to successfully introduce the Information Security Management System (ISMS) in compliance with ISO 27001 of the British Standards Institute (BSI).&lt;br /&gt;&lt;br /&gt;ISMS covers BTA-Online system that provides entities with online banking services. Within this certification international experts have named BTA-Online the product with a highest level of protection.&lt;br /&gt;&lt;br /&gt;ISO/IEC 27001:2005 certificate will enhance confidence of both investment companies and borrowers in BTA Bank to as regards its ability to protect information entrusted to it since the ISMS eliminates a risk of threat to information security.&lt;br /&gt;&lt;br /&gt;ISO/IEC 27001:2005 specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented Information Security Management System. Only this standard can be used in a certification by an international standard that specifies requirements to the ISMS.&lt;br /&gt;&lt;br /&gt;Development and introduction of the ISMS in compliance with ISO 27001 is a vital part of the IT strategy of Bank’s development and in general BTA strategy of turning into an international financial institution and raning among the major world’s banks.&lt;br /&gt;&lt;br /&gt;Russia-based InformZaschita has designed the ISMS for BTA Bank JSC and introduced it. &lt;br /&gt;&lt;br /&gt;Source: http://finchannel.com</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/1917137918339579367/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/1917137918339579367' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/1917137918339579367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/1917137918339579367'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/10/bta-bank-pioneered-information-security.html' title='BTA Bank pioneered information Security Management System in Kazakhstan'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-998383172538501488</id><published>2008-10-20T19:39:00.001-04:00</published><updated>2008-10-20T19:43:04.068-04:00</updated><title type='text'>&quot;The Renaissance the Credit&quot; has passed ISO 27001 certification</title><content type='html'>&lt;p&gt;«The Renaissance the Credit» has confirmed conformity of a control system with information safety to requests of international standard ISO/IEC 27001:2005.  ISO/IEC 27001:2005 establishes requests concerning definition, introductions, managements, monitoring, an estimation, support and constant perfection of a documentary control system by information safety (further – SUIB). This standard is the only thing suitable for certification by the international standard defining requests to SUIB. &lt;/p&gt; &lt;p&gt;«The qualitative system&lt;span id=&quot;more-36477&quot;&gt;&lt;/span&gt; of information safety is one of necessary and priority conditions of successful business dealing of the credit organisations, therefore we always watch closely conformity of our internal procedures to the international and Russian standards, – &lt;em&gt;the Chairman of board of KB«&lt;/em&gt; has commented &lt;em&gt;on the Renaissance the Capital »&lt;strong&gt;Alexey Levchenko&lt;/strong&gt;.&lt;/em&gt; – In our bank one of the most advanced IT Infrastructures is created, and we should be assured of reliable protection of confidential data». &lt;/p&gt; &lt;p&gt;Procedure of certification of a control system by information safety has been executed by the British institute of standards (British Standards Institution, further BSI) - the most authoritative service provider of certification of Control systems in the international market. It is remarkable, that «the Renaissance the Credit» became the first bank certificated BSI in Russia and the second Russian bank, received the certificate of conformity ISO 27001. &lt;/p&gt; &lt;p&gt;It is necessary to notice, that «the Renaissance the Credit» has conducted preparation for certification independently, without attraction of foreign advisers that confirms high qualification of the experts supplying information safety of bank, and also active sharing of a management in safety issues. The bank is not intended to remain in current borders of certification and plans its further expansion for all basic business processes.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Source: http://fin-forex.com&lt;br /&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/998383172538501488/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/998383172538501488' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/998383172538501488'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/998383172538501488'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/10/renaissance-credit-has-passed-iso-27001.html' title='&quot;The Renaissance the Credit&quot; has passed ISO 27001 certification'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-4915470512893200131</id><published>2008-10-20T19:35:00.001-04:00</published><updated>2008-10-31T15:11:17.884-04:00</updated><title type='text'>NCR Facility Attains ISO/IEC 27001 Certification</title><content type='html'>NCR Corp. announced its eCommerce Managed Hosting Services facility has achieved ISO/IEC 27001 certification recognizing the data center for &lt;a itxtdid=&quot;6843369&quot; target=&quot;_blank&quot; href=&quot;http://www.tradingmarkets.com/.site/news/Stock%20News/1921378/#&quot; style=&quot;border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;&quot; classname=&quot;iAs&quot; class=&quot;iAs&quot;&gt;meeting&lt;/a&gt; the International Standards Organization&#39;s exacting specifications for information security management. According to company officials, NCR&#39;s eCommerce Managed Hosting Services provides maximum secure protection of customer data for businesses running applications over the Internet.&quot;The ISO/IEC 27001 certification helps facilitate NCR&#39;s international expansion strategy to provide businesses in Europe and Asia Pacific with hosting solutions that deliver value for existing customer applications and help drive future capabilities including self-service and mobile transactions,&quot; said Chris Shea, NCR vice president, WCS Global Services Operations. &quot;This certification explicitly underscores our ability to securely manage a customer&#39;s confidential data, provide highly compliant hosting services and address additional industry specific certifications and requirements.&quot;&lt;p&gt;The eight-month ISO/IEC 27001 certification process involved process documentation and numerous site audits by ISO inspection teams and BSI Management Systems, a management systems certification body.&lt;/p&gt;&lt;p&gt;&quot;BSI was enthusiastic about the commitment and resources NCR implemented to ensure compliance with the rigorous ISO/IEC 27001 certification requirements,&quot; said Todd VanderVen, president of BSI Management Systems America. &quot;With high standards of security, availability and risk management practices in place, NCR is well-positioned to provide customers with information security management processes and has established a structured framework to promote continuous improvement in meeting the specific needs of its diverse customers.&quot;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Source: http://www.tradingmarkets.com/&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/4915470512893200131/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/4915470512893200131' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4915470512893200131'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/4915470512893200131'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/10/ncr-facility-attains-isoiec-27001.html' title='NCR Facility Attains ISO/IEC 27001 Certification'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-6228402629813008346</id><published>2008-10-14T19:47:00.000-04:00</published><updated>2008-10-20T19:48:24.631-04:00</updated><title type='text'>M I G awarded ISO 27001</title><content type='html'>ISO Certifications awarded to M I G Investments for meeting quality and security standards&lt;br /&gt;M I G Investments has been awarded the ISO 9001:2000 certification in recognition of its standardized Quality Management best-practices, and the ISO 27001:2005 certification for standardized Information Security techniques. The move comes as M I G Investments leverages its international expertise as a major Swiss, online FX broker by bringing customers quality services, innovation, technology and high security standards.&lt;br /&gt;&lt;br /&gt;Source: http://www.forex-blogs.net/</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/6228402629813008346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/6228402629813008346' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/6228402629813008346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/6228402629813008346'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/10/m-i-g-awarded-iso-27001.html' title='M I G awarded ISO 27001'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-5666723855984325448</id><published>2008-10-11T19:15:00.000-04:00</published><updated>2008-10-20T19:16:08.681-04:00</updated><title type='text'>Affinion Group Receives ISO Certification</title><content type='html'>&lt;p&gt;The &lt;a href=&quot;http://www.forbes.com/lists/2006/21/biz_06privates_Affinion-Group_GWXS.html&quot;&gt;Affinion Group&lt;/a&gt;, a global leader in affinity marketing, has been awarded the esteemed ISO 27001 certification, the highest international standard for information security management in the world.&lt;/p&gt; &lt;p&gt;The group was lauded for their high information security practices and policies. Due to the global affinity marketing firm’s dedication to shield its clients from identity theft and scammers, the Affinion Group is the only company in the industry and one of the 50 companies in the United States that was given the prestigious ISO 27001 Certification. Only 4,100 companies all over the world hold the same recognition.&lt;/p&gt; &lt;p&gt;Apart from the Affinion Group, other U.S. organizations that share the same commendation are Sun Microsystems, Bechtel Corp., Reuters America, The World Bank, Citigroup Technology, and Xerox Corp. among others.&lt;/p&gt; &lt;p&gt;The ISO Certification establishes Affinion’s longstanding commitment in seeking innovations that would further improve information security and reduce the incidences of identity theft and scams in their industry. Robert G. Rooney, Vice-President of the Affinion Group, stated the company strives to “raise the bar for the practices in our industry.”&lt;/p&gt; &lt;p&gt;An ISO certification indicates that a company has put into practice an information security management system that surpasses even the strictest security standards on a global scale.&lt;/p&gt; &lt;p&gt;The following are several factors that contributed to Affinion’s ISO Certification:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Implementation of best practice across all information security domains;&lt;/li&gt;&lt;li&gt;Putting up of a strong security outline that entails operation, monitoring, review, maintenance and development;&lt;/li&gt;&lt;li&gt;Systematic management of incidents with clear and timely escalation paths.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;With its ISO certification, the &lt;a href=&quot;http://company.monster.com/affinion/&quot;&gt;Affinion Group&lt;/a&gt; has a strong foundation from where they could base their information security framework for 2008.&lt;/p&gt; &lt;p&gt;Operating for 35 years, the Affinion Group continues to enhance the value of its partners’ customer relationships by strengthening and marketing valuable loyalty, membership, checking account, insurance and other compelling products and services.&lt;/p&gt; &lt;p&gt;View the source press release from the &lt;a href=&quot;http://www.reuters.com/article/pressRelease/idUS150000+10-Jan-2008+PRN20080110&quot;&gt; Affinion Group&lt;/a&gt;.&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/5666723855984325448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/5666723855984325448' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/5666723855984325448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/5666723855984325448'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/10/affinion-group-receives-iso.html' title='Affinion Group Receives ISO Certification'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-6345902437947948042</id><published>2008-10-10T19:12:00.000-04:00</published><updated>2008-10-20T19:14:57.812-04:00</updated><title type='text'>EOL earns its fourth ISO accolade</title><content type='html'>&lt;div id=&quot;post&quot;&gt;                     &lt;div class=&quot;content&quot;&gt;  &lt;p&gt;VAR EOL IT has bagged an International Standards Organisation (ISO) certification in security management and plans to use it to push into the public sector.&lt;/p&gt;  &lt;p&gt;The firm has completed certification for the ISO 27001 for information security management systems, which less than one per cent of all UK firms have so far completed.&lt;/p&gt;  &lt;p&gt;This brings the firm’s number of ISO qualifications to four; the others being ISO 18001 for occupational health and safety management, ISO 9001 for quality administration systems and ISO 14001 for environmental management systems.&lt;/p&gt;  &lt;p&gt;Richard Parker, managing director of EOL IT, said: “This latest ISO is all about data security. A number of our competitors have this, but the immediate benefit for us is when tendering to clients.”&lt;/p&gt;  &lt;p&gt;Parker added that the firm intends to go for larger public sector contracts now that it has four ISO standards. “There is only one other firm that I know in our sector with all four ISO certifications. It is all about putting in best practice to the business.”&lt;/p&gt;&lt;p&gt;Source: http://www.channelweb.co.uk/crn/news/2227374/eol-earns-fourth-iso-accolade-4253635&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;  &lt;/div&gt;             &lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/6345902437947948042/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/6345902437947948042' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/6345902437947948042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/6345902437947948042'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/10/eol-earns-its-fourth-iso-accolade.html' title='EOL earns its fourth ISO accolade'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-6176385809060378867</id><published>2008-10-09T19:44:00.000-04:00</published><updated>2008-10-20T19:45:38.227-04:00</updated><title type='text'>ISO-27001 Quick Reference</title><content type='html'>&lt;p&gt;I waffle on about this thing a lot - because I like it.&lt;/p&gt; &lt;p&gt;The fundamental triangle of all ISO business standards now rests upon ISO9001, ISO14001 and ISO27001. The documentation is meant to be structured in such a way that the “01″ document is the standard and the “02″ document is the guide. So ISO27001 is the standard and ISO27002 is the guide to that standard (neat).&lt;/p&gt; &lt;p&gt;&lt;a href=&quot;http://www.ipvideo.ie/Downloads/ISO27002_spider_chart.pdf&quot;&gt;Here’s a handy spider diagram&lt;/a&gt; that gives you all the headings from ISO27002. I use it as a quick tick list to guide people towards making a “scope of applicability” for their business security needs.&lt;/p&gt; &lt;p&gt;Note that the headings go from (4) to (15)…there is no (1) to (3)…this is one of the great unfathomable mysteries of ISO. We are unworthy of controls (1) to (3), perhaps in an afterlife these ultimate truths will be revealed to us…or maybe they just forget to include them, I dunno…&lt;/p&gt; &lt;p&gt;Anyway, I hope some folk find this useful&lt;/p&gt;&lt;p&gt;Source: http://ipvideo.ie/&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/6176385809060378867/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/6176385809060378867' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/6176385809060378867'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/6176385809060378867'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/10/iso-27001-quick-reference.html' title='ISO-27001 Quick Reference'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-6671732758097295535</id><published>2008-10-03T15:40:00.002-04:00</published><updated>2008-10-03T15:50:40.703-04:00</updated><title type='text'>ISO 27000 Serie Update!</title><content type='html'>The ISO/IEC 27000-series numbering (“ISO27k”) has been reserved for a family of information security management standards, similar to the very successful ISO 9000 family of quality assurance standards and derived from a British Standard called &lt;a href=&quot;http://www.iso27001security.com/html/27002.html#HistoryOfISO17799&quot;&gt;BS 7799&lt;/a&gt;.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The following standards are either already published (shown in red) or works in progress:&lt;br /&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27000.html&quot;&gt;ISO/IEC 27000&lt;/a&gt; - will provide an overview/introduction to the ISO27k standards as a whole plus the specialist vocabulary used in ISO27k. Once approved by the members of ISO/IEC JTC1/SC27, it should be published later this year.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27001.html&quot;&gt;ISO/IEC 27001:2005&lt;/a&gt; is the Information Security Management System requirements standard (specification) against which over 4,700 organizations have been certified compliant.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27002.html&quot;&gt;ISO/IEC 27002:2005&lt;/a&gt; is the code of practice for information security management describing a comprehensive set of information security control objectives and a set of generally accepted good practice security controls.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27003.html&quot;&gt;ISO/IEC 27003&lt;/a&gt; will provide implementation guidance for ISO/IEC 27001. &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27004.html&quot;&gt;ISO/IEC 27004&lt;/a&gt; will be an information security management measurement standard to help improve the effectiveness of your ISMS. &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27005.html&quot;&gt;ISO/IEC 27005:2008&lt;/a&gt; is a new information security risk management standard released in June 2008.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27006.html&quot;&gt;ISO/IEC 27006:2007&lt;/a&gt; is a guide to the certification or registration process for accredited ISMS certification or registration bodies.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27007.html&quot;&gt;ISO/IEC 27007&lt;/a&gt; will be a guideline for auditing Information Security Management Systems. &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27008.html&quot;&gt;ISO/IEC TR 27008&lt;/a&gt; will provide guidance on auditing information security controls.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27010.html&quot;&gt;ISO/IEC 27010&lt;/a&gt; will provide guidance on sector-to-sector interworking and communications for industry and government, supporting a series of sector-specific ISMS implementation guidelines starting with ISO/IEC 27011. &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27011.html&quot;&gt;ISO/IEC 27011&lt;/a&gt; will be information security management guidelines for telecommunications (also known as X.1051) and will be released soon. &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27031.html&quot;&gt;ISO/IEC 27031&lt;/a&gt; will be an ICT-focused standard on business continuity. &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27032.html&quot;&gt;ISO/IEC 27032&lt;/a&gt; will be guidelines for cybersecurity. &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27033.html&quot;&gt;ISO/IEC 27033&lt;/a&gt; will replace the multi-part ISO/IEC 18028 standard on IT network security.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27034.html&quot;&gt;ISO/IEC 27034&lt;/a&gt; will provide guidelines for application security. &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/27799.html&quot;&gt;ISO 27799&lt;/a&gt;, although not strictly part of ISO27k, provides health sector specific ISMS implementation guidance.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.iso27001security.com/html/other_27k.html&quot;&gt;Other ISO27k&lt;/a&gt; is a holding page with preliminary information on more ISO27k standards including sector/industry-specific ISMS implementation guidelines whose scopes and ISO27k numbers have not yet been determined. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The names and content of as-yet unpublished standards may well change prior to their publication, especially the early drafts.&lt;/p&gt;&lt;p&gt;Source: &lt;a href=&quot;http://www.iso27001security.com/&quot;&gt;http://www.iso27001security.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/6671732758097295535/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/6671732758097295535' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/6671732758097295535'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/6671732758097295535'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/10/iso-27000-serie-update.html' title='ISO 27000 Serie Update!'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-5405835281390004397</id><published>2008-09-24T08:16:00.000-04:00</published><updated>2008-09-24T08:17:01.743-04:00</updated><title type='text'>1st ISO 27001 certification in France for security audits of IT systems</title><content type='html'>&lt;div&gt;Solucom, leading player in IT security, has just received certification to ISO/IEC 27001:2005 for its auditing services of the security of IT systems.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This internationally recognized certification guarantees the implementation of a management system and both organizational and technical security measures. It involves a regular reassessment of risks and facilitates continuous improvement. Solucom’s auditing service was audited and certified by LSTI[1], which is accredited by COFRAC[2].&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Laurent Bellefin, Director of Security Operations at Solucom states that, “This is the first 27001 certification in France for security audits of IT systems[3]. We carry out more than a hundred audits annually, which involves handling sensitive client data. The certification and the regular, independent follow-up inspections are our clients’ guarantee that we are outstanding in the protection of the data they provide us.”&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Obtaining the certification also enhances what Solucom has to offer in risk management consulting. Gérôme Billois, Security Manager, adds, “This certification demonstrates our commitment to ISO 27001 and our skill in implementing it. It is yet a further proof of our ability to support our major account clients in their own plans for certification or implementation of the standard.”&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In France ISO 27001 is eliciting major interest among big companies. “Implementing the standard lets you formalize your security initiatives and ensure you are on top of the risks and constantly improving, which are essential points in today’s governance,” adds Gérôme Billois.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/5405835281390004397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/5405835281390004397' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/5405835281390004397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/5405835281390004397'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/09/1st-iso-27001-certification-in-france.html' title='1st ISO 27001 certification in France for security audits of IT systems'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-2507565029983521685</id><published>2008-09-23T15:55:00.000-04:00</published><updated>2008-09-23T15:56:20.209-04:00</updated><title type='text'>eHosting DataFort Achieves ISO 27001</title><content type='html'>&lt;div&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: rgb(204, 0, 0);&quot;&gt;Region&#39;s Leading Service Provider Enhances Customer Confidence by Implementing International Security Standard Across Business Units&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dubai: 23 September, 2008 - eHosting DataFort (EHDF), the region&#39;s leading IT outsourcing service and consulting services provider and a member of TECOM Investments, today announced its internal business units have successfully implemented the ISO 27001 Information Security Management System (ISMS), an international standard for addressing information security concerns.&lt;/div&gt;&lt;div&gt;The decision to implement the management system across all departments including its Data Centres and security operations confirms eHosting Datafort&#39;s continual commitment towards its customers by improving the security of business information, making it the first ever service provider in the region and among a select few worldwide to implement such a system throughout the organization.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Implementing ISO 27001 comes as part of eHosting DataFort&#39;s certification process in establishing a Corporate Governance and Management System (CGMS) program which includes a host of international standard certifications including the ISO 20000, ISO 9000 and BS 25999. These certifications will be effective across business units at eHosting DataFort shortly.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Mohamed Fouz, CEO of eHosting DataFort, said: &quot;Information security is a critical component of our business. Protecting business information through a robust security management system using effective security controls is a key management responsibility.&quot;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;eHosting DataFort&#39;s initiative comes as a proactive response to providing customers a more agile and secure infrastructure through establishing the Corporate Governance and Management System program, considering the recent security breaches that have affected businesses across the region.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&quot;Implementing ISO 27001 and complying with international standards will enhance the customers overall confidence in eHosting DataFort,&quot; added Fouz.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ahmed Baig, Manager, Security Consulting at eHosting DataFort, said: &quot;Many organizations believe that securing their IT systems will guarantee the security of critical information. But as many organizations have realized, security breaches are the result of absence of governance including processes and controls. eHosting DataFort is not only committed to raising the level of security standards in the region, but also firmly believes in living up to its commitment of providing reliable and secure services to its customers.&quot;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;eHosting DataFort&#39;s consulting team has also successfully implemented ISO 27001 at Dubai Aluminum Company (DUBAL), Kuwait National Petroleum Company (KNPC), and more recently, at the Emirates Identity Authority (EIDA).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Committed to promoting information security within the region, the team at eHosting DataFort manages a 24/7 Security Operation Centre for monitoring and managing the security of leading organizations across the MENA region.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In fact their Corporate Social Responsibility (CSR) objective focuses on spreading awareness of information security and technology amongst the community focusing on Schools, Universities and Government/Public sectors through the Marifaty (My Knowledge) and Muthabara (Persistence) programmes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;eHosting DataFort offers consulting and advisory services in Information security, IT service management, business continuity and quality management systems.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/2507565029983521685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/2507565029983521685' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/2507565029983521685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/2507565029983521685'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/09/ehosting-datafort-achieves-iso-27001.html' title='eHosting DataFort Achieves ISO 27001'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-566657849185050213</id><published>2008-09-23T15:39:00.000-04:00</published><updated>2008-09-23T15:40:24.814-04:00</updated><title type='text'>Health information security standard issued</title><content type='html'>&lt;div&gt;In an effort to help protect personal health care information, the International Organization for Standardization (ISO) has published a new standard that specifies controls for managing health information security and utilizing best practices.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;According to an ISO statement, the new standard - ISO 27799:2008 - applies to all health information in “whatever form the information takes, whatever means are used to store it and whatever means are used to transmit it.”&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This new standard, announced in late August, addresses the use of internet and wireless technologies to share personal medical information, and the need to better protect confidentiality and keep data private.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt; “An important consideration was the adaptability of the guidelines, bearing in mind that many health professionals work as solo health providers or in small clinics that lack dedicated IT resources to manage information security,” the statement said.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Richard Rushing, CSO at wireless security firm AirDefense, told SCMagazineUS.com on Wednesday that the standard shows that many organizations have the same issues and that similar guidelines should be followed.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;“If followed, it would make information more secure,” Rushing said, “but there is usually nothing that specifically states that it is to be followed, except for maybe an audit that may have occurred sometime in the past.”&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The ISO standard will do things that Health Insurance Portability and Accountability Act (HIPAA)-related laws cannot do, said Rani Osnat, vice president for marketing with Sentrigo, a database security company.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;“HIPAA protects privacy, but it is not an IT standard,” Osnat told SCMagazineUS.com. “It doesn&#39;t do anything to protect data from an IT standpoint. This ISO [standard] will provide a much-needed benchmark for health organizations to follow to encourage better IT security.”&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Source: http://www.scmagazineus.com&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/566657849185050213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/566657849185050213' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/566657849185050213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/566657849185050213'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/09/health-information-security-standard.html' title='Health information security standard issued'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-987581787108127885.post-9067080853954953886</id><published>2008-09-22T21:09:00.000-04:00</published><updated>2008-09-23T21:10:48.867-04:00</updated><title type='text'>Press Release - New Brand</title><content type='html'>&lt;span class=&quot;Apple-style-span&quot; style=&quot;border-collapse: collapse; font-family: &#39;times new roman&#39;; &quot;&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: justify; margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif; &quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;New York, September 22th &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;– Axur and Realiso Corp. announce that from this date, &lt;b&gt;Axur ISMS &lt;/b&gt;solution&lt;b&gt; &lt;/b&gt;has a new brand and is called &lt;/span&gt;&lt;span lang=&quot;PT-BR&quot; style=&quot;font-size: 12pt; &quot;&gt;&lt;a href=&quot;http://www.realiso.com/realisms/&quot; style=&quot;color: purple; text-decoration: underline; &quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Real ISMS&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;, property of &lt;/span&gt;&lt;span lang=&quot;PT-BR&quot; style=&quot;font-size: 12pt; &quot;&gt;&lt;a href=&quot;http://www.realiso.com/&quot; style=&quot;color: purple; text-decoration: underline; &quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Realiso Corp&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif; &quot;&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;&lt;o:p&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: 15px; &quot;&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;Please update your bookmark. Get access to Real ISMS site at &lt;/span&gt;&lt;span lang=&quot;PT-BR&quot; style=&quot;font-size: 12pt; &quot;&gt;&lt;a href=&quot;http://www.realiso.com/realisms&quot; style=&quot;color: purple; text-decoration: underline; &quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;www.realiso.com/realisms&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif; &quot;&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;&lt;o:p&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: 15px; &quot;&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;For more information please contact us at &lt;/span&gt;&lt;span lang=&quot;PT-BR&quot; style=&quot;font-size: 12pt; &quot;&gt;&lt;a href=&quot;mailto:contact@realiso.com&quot; style=&quot;color: blue; text-decoration: underline; &quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;contact@realiso.com&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif; &quot;&gt;&lt;span lang=&quot;PT-BR&quot; style=&quot;font-size: 12pt; &quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif; &quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: 16px; font-weight: bold;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif; &quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: 16px; font-weight: bold; &quot;&gt;Realiso Corp.&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif; &quot;&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;626, Glenn Curtiss Blvd - Uniondale&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif; &quot;&gt;&lt;span style=&quot;font-size: 12pt; &quot;&gt;New York, USA&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://axurblog.blogspot.com/feeds/9067080853954953886/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/987581787108127885/9067080853954953886' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/9067080853954953886'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/987581787108127885/posts/default/9067080853954953886'/><link rel='alternate' type='text/html' href='http://axurblog.blogspot.com/2008/09/press-release-new-brand.html' title='Press Release - New Brand'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>