India's leading Information Risk Management (IRM) company
  About CII SecureSynergy: ISO27001 certified company          
 
IRM HOME
   
Introduction
Services
  - Consulting
  - Training
Newsletter
News
Security Library
InfoSec Glossary
Contact / Feedback
   
 
AUDIT FACILITATION
Vet an Indian company
 
 
END-USER CERTIFICATION
Certified Information Security Aware User (CISAU)
 
 
CII HOME
Other CII Services
:: WTO
:: TQM
:: TPM
:: Technology & IPR
:: SME
:: Skills Initiative
:: Library
:: IRM
:: Invest India Services
:: Green Business
:: Exports
:: Environment Mgmt
:: Energy
:: Corporate Advisory
:: Climate Change
:: Business Development Services
 
 
 
 
 
Time Synchronization — Vital for Info-security

'A man with one clock knows the time, a man with two clocks is not sure'. Unsynchronized computer clocks in the enterprise Information Infrastructure would have significant impact on network and security operations...

 
Manage your Information Security

A well designed information security strategy enables organisations to integrate information security with business strategy and planning, and defines the framework through which organisational information risks can be securely managed.

 
Data Centre Security Issues

Emerging datacentre trends like virtualisation, grid and utility computing, ILM and Web services point to an environment that is powerful yet fragile, mandating concerted focus on datacentre security.

 
Survivability and Availability of Information Systems

Since no system is entirely impervious to attacks in an unbounded environment, there is now an intense focus on ensuring survivability of mission critical systems and essential services.

 
Emerging Security Technologies

The ability to deep-inspect a packet's payload has opened up a whole new world of application layer protection technologies. From an infrastructure perspective, the focus of emerging security technologies is moving upstream from platforms to enterprise networks, and on to the Internet itself...

 
Crime & Sasser

The Sasser worm will leave in its wake an estimated one million infected computers… And yet, the Sasser worm itself isn't the security issue.

 
Implementing Robust Information Security Policies

Today security policies are driven by the compulsion to comply with legislative and regulatory obligations; and for underpinning business expansion strategies. From being mere instruments of risk management, security policies have morphed into becoming vital enablers of business operations and strategic imperatives.

 
Target-based IDS — Cutting Through Network Noise

The new target-based IDS reduces false positives and squelches alerts to an astonishing degree. The act of determining the target's vulnerability before raising an alarm is what differentiates target-based IDS from the traditional IDS.

 
Intrusion Prevention System — The New Crown Jewel

In an unbounded world where network perimeters are obsolete, and where the distinction between insiders and outsiders is diffused, traditional security tools fall short. In this world, IPS is the new crown jewel of enterprise security!

 
Information Security in Unbounded Environments

Today, bounded environments ensconced within clearly demarcated perimeters are giving way to a milieu where gateways are obsolete. In this environment, the distinction between insiders and outsiders is blurred, and organisations neither have central administrative control over their information systems nor do they have access to global view of events occurring therein.

 
Future of Wireless LAN Security

Wireless connectivity is set to become the biggest thing in computing since the Internet. With ongoing WLAN security initiatives this may well become true, painlessly, and sooner than predicted.

 
Countering Social Engineering Attacks

People are the weakest link in the information security chain. Social engineering is a hacking technique that relies on weaknesses in human nature, rather than weaknesses in hardware, software, or network design.

 
Security Models

Enterprise security architectures flow from security policies, which are based on estimated risk to the enterprise. Security models provide a quantitative technique of encapsulating the policies into executable architectures.

 
Defining Information Threats

Enterprise Information Infrastructures have become critical 'centres of gravity'. Implementing robust information security controls in the enterprise is no longer a matter of choice.

 
Open Source Software — Panacea or Peril?

Does the open nature of Open Source actually make it more vulnerable to attack? Or, does the fact that code can be reviewed and bug fixes be submitted make Open Source superior to proprietary software?

 
Policing Systems Assets Through Infosec Policies

Information technology is strategic to enterprise growth. Today, information assets have to be protected with the same level of commitment and vigilance that the management devotes to financial supervision and overall enterprise governance.

 
Surviving Disaster

Business continuity and disaster recovery planning are now accepted as basic requirements for every business organisation. It is widely accepted that a detailed Disaster Recovery Plan should not only exist, but should be up to date. It should reflect the actual on-going needs of the business activity or function.

 
Information Security: A New Approach

The role of information security has changed across the past few years. Traditional definition of protecting networks and the Datacenter has undergone a shift in focus resulting in enablement of businesses with security solutions actually moving your business forward or even to the next step.

 
Cyber Attacks: Defending our Electronic Frontiers

Even as countries and organisations are gearing to defend themselves from cyber criminals and terror mongers, newer methods of destruction are being devised by potential attackers. The Internet, which started as an information dissemination medium, has now become the ground-zero on which tech savvy terrorists and criminals are 'settling scores'.

 
Autonomic Systems - Combating DDoS Attacks

Distributed Denial-of-Service attacks are getting more and more sophisticated, pre-meditated and well coordinated. The attacks are more often than not focused on the core Internet infrastructure rather than isolated victims.

 
Secure Media Disposal - The importance of erasing data irretrievably

'Electronic scavenging' for retrieval of sensitive data is a reality in corporate espionage today. 'Degaussing' completely and irretrievably erases the information stored on the magnetic surface.

 
The single largest factor for Security Breaches

According to the CSI/FBI Survey 2002, over 94% of large corporations have had sizeable downtime and financial losses due to malicious code attacks. As per the CII-PwC Survey 2002, 75% corporates in India have had serious incidences of malicious code attacks "forcing them to shut down external connections to the Internet, resulting in large losses due to downtime and lost business opportunities".

 
What is your Incident Response Quotient?

It is good to have a snare and a trigger, but without the trap it makes no sense. Incident detection is important; but incident response is more critical. You realise you are being hacked. What do you do? Press the panic button?

 
 
 
 
 
 
 
 
 
 
 
 
 
Information Risk Management (IRM) Service for Industry
in partnership with SecureSynergy
IT SECURITY TRAINING
CII has designed courses for Board of Directors, CEOs, CFOs, CIOs and Management Decision Makers in areas affecting IT Security Governance and implementation of enterprise-wide security programs.
::. MUST  READ .::
Role of IT in Corp Governance
IT Security Governance
Information Security - A Business Enabler
IRM - A BPO Imperative

Say yes to
S T A N D A R D S  &  R E G U L A T O R Y
C O M P L I A N C E

Regulation establishes security duties and standards to foster better governance...
 
 
 
 
 
 
All rights reserved :: Confederation of Indian Industry (CII) © Copyright 2004-2008
Copyright  ::  Disclaimer  ::  Privacy