Security Mgt U10, world class security infrastructure

Description

IYM001 Mind Map on Security Mgt U10, world class security infrastructure, created by jjanesko on 14/04/2013.
jjanesko
Mind Map by jjanesko, updated more than 1 year ago
jjanesko
Created by jjanesko about 11 years ago
116
19

Resource summary

Security Mgt U10, world class security infrastructure
  1. ISO ceritifcation benefits
    1. business partner trust
      1. customer confidence
        1. leverage for security programmes
          1. mgt attention for deficiencies
            1. public recognition
              1. efficient, low cost
                1. more control for external auditors
                2. importance of security is rising
                  1. increasing threats
                    1. increasing expectations
                      1. increasing exposure
                      2. cyberspace wars
                        1. kinds
                          1. espionage
                            1. sabotage
                              1. deception
                              2. knowledge has become power
                                1. power struggles over control of information
                                2. information has become increasingly available
                                  1. growth in information brokering
                                3. cyberterrorism
                                  1. growth of diversity
                                    1. growth in extreme advocates
                                    2. globalisation of IT
                                      1. terrorists acquire IT capability
                                        1. terrorism becomes transnational
                                      2. challenges to secure environments
                                        1. vendors' intrinsic security
                                          1. interoperability, manageability, scalability
                                          2. good architecture
                                            1. anticipates problesm
                                              1. avoids single points of failure
                                                1. extends across enterprise
                                                  1. flexible
                                                    1. continuous improvement
                                                      1. long-lasting infrastructure
                                                      2. important control areas
                                                        1. technology
                                                          1. applications
                                                            1. architecture
                                                              1. infrastructure
                                                                1. adopted standards

                                                                  Attachments:

                                                                2. people

                                                                  Attachments:

                                                                  1. org structure
                                                                    1. roles and responsibilities
                                                                      1. culture & attitutdes
                                                                        1. skills & training
                                                                        2. processes
                                                                          1. compliance
                                                                            1. procedures
                                                                          2. 3 dimensional risk assessment
                                                                            1. project
                                                                              1. value chain
                                                                                1. asset
                                                                                2. incident response scope

                                                                                  Attachments:

                                                                                  1. because of deperimiterization, we need...
                                                                                    1. industry standards
                                                                                      1. assurance processes that build trust across boundaries
                                                                                        1. agreed protocols & strength of mechanisms
                                                                                          1. reconized classification schemes for data, systems and connections
                                                                                            1. consistent user authentication standard
                                                                                              1. common security policy definition language
                                                                                              Show full summary Hide full summary

                                                                                              Similar

                                                                                              Security Mgt, ISO 27001, PDCA
                                                                                              jjanesko
                                                                                              Exemplary Assignment Answers
                                                                                              jjanesko
                                                                                              Security Mgt, Flashcards for ISO 27000 series
                                                                                              jjanesko
                                                                                              Security Mgt U5, risk analysis and mgt (part 1)
                                                                                              jjanesko
                                                                                              Security Mgt U8, Information Assurance
                                                                                              jjanesko
                                                                                              Security Mgt U3, BS7799 (Part 2)
                                                                                              jjanesko
                                                                                              Security Mgt U5, quantitative risk assessment forumula (image)
                                                                                              jjanesko
                                                                                              Security Mgt U8, Incident Recovery Image
                                                                                              jjanesko
                                                                                              Security Mgt U3, BS7799 (Part 1)
                                                                                              jjanesko
                                                                                              Security Mgt U5, Risk Analysis Methods and Tools (image)
                                                                                              jjanesko
                                                                                              Security Mgt U5, risk analysis & mgt (part 2)
                                                                                              jjanesko