<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>ITBE: Message List</title>
    <link>http://www.itbusinessedge.com/cm/index.jspa?view=discussions</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    <pubDate>Sat, 21 Nov 2009 00:55:25 GMT</pubDate>
    <generator>Clearspace 2.5.5 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2009-11-21T00:55:25Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2019?tstart=0#2019</link>
      <description>I think Royce makes a great point when he says that these controls will not always prevent disaster from striking but will protect the company from any ensuing fines or lawsuits.  When I used to work for a credit card processing company, certain</description>
      <pubDate>Sat, 21 Nov 2009 00:55:25 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2019?tstart=0#2019</guid>
      <dc:date>2009-11-21T00:55:25Z</dc:date>
      <clearspace:dateToText>9 hours, 32 minutes ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2018?tstart=0#2018</link>
      <description>It matters where you get your controls to an extent.  Warrick was right, enough time and effort has been spent on creating proven controls so as long as your controls come from a solid source such as ISO17799 and CobiT the company should be fine.  When</description>
      <pubDate>Sat, 21 Nov 2009 00:44:47 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2018?tstart=0#2018</guid>
      <dc:date>2009-11-21T00:44:47Z</dc:date>
      <clearspace:dateToText>9 hours, 43 minutes ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2017?tstart=0#2017</link>
      <description>Mille, I do agree that companies should acknowledge threats and focus on the best interest of the organizational system and technical, operational, and management security controls should be considered. However, I also think that depending on the type</description>
      <pubDate>Fri, 20 Nov 2009 04:57:25 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2017?tstart=0#2017</guid>
      <dc:date>2009-11-20T04:57:25Z</dc:date>
      <clearspace:dateToText>1 day, 5 hours ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2016?tstart=0#2016</link>
      <description>Yes, it does matter where controls are obtained. When choosing which controls to implement, organizations should focus on the greatest risks and work to mitigate them at the lowest cost with minimal impact on the company mission. In implementing</description>
      <pubDate>Fri, 20 Nov 2009 04:50:22 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2016?tstart=0#2016</guid>
      <dc:date>2009-11-20T04:50:22Z</dc:date>
      <clearspace:dateToText>1 day, 5 hours ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2015?tstart=0#2015</link>
      <description>Great point to acknowledge the standardized controls which should be used should depend on what system you are trying to assess. It makes since to use whatever controls that are most suited for your business.  I like the fact that there are so many</description>
      <pubDate>Fri, 20 Nov 2009 04:48:54 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2015?tstart=0#2015</guid>
      <dc:date>2009-11-20T04:48:54Z</dc:date>
      <clearspace:dateToText>1 day, 5 hours ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2014?tstart=0#2014</link>
      <description>It do not matter where you get your controls as long as you acknowledge your threats and your focus is on the best interest of the organizational system.  As it was mentioned Cobit (Control Objectives for Information and related Technology) uses a set</description>
      <pubDate>Fri, 20 Nov 2009 04:35:01 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2014?tstart=0#2014</guid>
      <dc:date>2009-11-20T04:35:01Z</dc:date>
      <clearspace:dateToText>1 day, 5 hours ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2012?tstart=0#2012</link>
      <description>/* Style Definitions */table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin-top:0in;</description>
      <pubDate>Fri, 20 Nov 2009 04:00:58 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2012?tstart=0#2012</guid>
      <dc:date>2009-11-20T04:00:58Z</dc:date>
      <clearspace:dateToText>1 day, 6 hours ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2013?tstart=0#2013</link>
      <description>Dawit, I agree with your geographic assesment. I found the comparison chart rather informative. The ISO 17799 standard is very useful since it appears to have wide acceptance. I agree with your assesment of a  standardization of controls for comparison</description>
      <pubDate>Fri, 20 Nov 2009 04:13:28 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2013?tstart=0#2013</guid>
      <dc:date>2009-11-20T04:13:28Z</dc:date>
      <clearspace:dateToText>1 day, 6 hours ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2011?tstart=0#2011</link>
      <description>Jeff, &amp;nbsp; You make a good point.  Maybe my criticism of the regulatory industrywas a little harsh.  Their intended purpose is a good one, and for the most part they serve to protect consumers and clientele just as much as the company's that invest in</description>
      <pubDate>Fri, 20 Nov 2009 03:17:28 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2011?tstart=0#2011</guid>
      <dc:date>2009-11-20T03:17:28Z</dc:date>
      <clearspace:dateToText>1 day, 7 hours ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2010?tstart=0#2010</link>
      <description>i. Region(s) of operation i.e. City, State, Country, Continent,    International ii. Industry i.e. Medical, Manufacturing, Government etc. iii. Size of organization iv. Command and Control topology i.e. Centralized, Autonomous etc. you made nice point</description>
      <pubDate>Thu, 19 Nov 2009 23:32:26 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2010?tstart=0#2010</guid>
      <dc:date>2009-11-19T23:32:26Z</dc:date>
      <clearspace:dateToText>1 day, 10 hours ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2009?tstart=0#2009</link>
      <description>Yes it really matters where we get our controls form my whole perspective is focus  on regional  matters for instance if we doing our risk assessment for a company lets located in japans we have to take in consideration  of the compliance that is</description>
      <pubDate>Thu, 19 Nov 2009 23:24:30 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2009?tstart=0#2009</guid>
      <dc:date>2009-11-19T23:24:30Z</dc:date>
      <clearspace:dateToText>1 day, 11 hours ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2008?tstart=0#2008</link>
      <description>Royce, &amp;nbsp; Keep in mind all of the "standards" are based onproven strategies and are to be used as a guide that is documented and has been thoroughly put into practice and been tested. When adding a safeguard, all anyone can go on is what has been</description>
      <pubDate>Thu, 19 Nov 2009 23:06:41 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2008?tstart=0#2008</guid>
      <dc:date>2009-11-19T23:06:41Z</dc:date>
      <clearspace:dateToText>1 day, 11 hours ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2007?tstart=0#2007</link>
      <description>Peace of mind is a huge factor.    The sources and types of controls used obviously have a tremendous impact on the likelihood of the occurrence of a particular risks/threats.    However, nothing is full proof.    The controls are meant to mitigate</description>
      <pubDate>Thu, 19 Nov 2009 21:29:13 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2007?tstart=0#2007</guid>
      <dc:date>2009-11-19T21:29:13Z</dc:date>
      <clearspace:dateToText>1 day, 12 hours ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Selling Management on Architecture</title>
      <link>http://www.itbusinessedge.com/cm/message/2006?tstart=0#2006</link>
      <description>"How do I sell executive management on developing a Architecture program?"</description>
      <pubDate>Thu, 19 Nov 2009 21:26:18 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2006?tstart=0#2006</guid>
      <dc:date>2009-11-19T21:26:18Z</dc:date>
      <clearspace:dateToText>1 day, 13 hours ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/2005?tstart=0#2005</link>
      <description>As stated in previous posts.    A company may obtain controls from a variety of sources.    Risk analysis/assessment/management has been in use for quite some time now.    Such techniques are used as a means to perpetuate the positive flow of business</description>
      <pubDate>Thu, 19 Nov 2009 21:08:33 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/2005?tstart=0#2005</guid>
      <dc:date>2009-11-19T21:08:33Z</dc:date>
      <clearspace:dateToText>1 day, 13 hours ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/1998?tstart=0#1998</link>
      <description>Jeff,      I agree, regulatory compliance is a major driver for the adoption of many controls. Most compliance reglations have been mandated based on the consensus that general implementation of these standards will create transparency for business,</description>
      <pubDate>Tue, 17 Nov 2009 03:24:54 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/1998?tstart=0#1998</guid>
      <dc:date>2009-11-17T03:24:54Z</dc:date>
      <clearspace:dateToText>4 days, 7 hours ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/1997?tstart=0#1997</link>
      <description>Great points Warrick. When selecting controls there is "no need to recreate the wheel". Usually the time constraints on meeting these requirements wouldn't allow for that much piloting and testing anyway. &amp;nbsp; The factors you mentioned along with the</description>
      <pubDate>Tue, 17 Nov 2009 02:10:57 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/1997?tstart=0#1997</guid>
      <dc:date>2009-11-17T02:10:57Z</dc:date>
      <clearspace:dateToText>4 days, 8 hours ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/1996?tstart=0#1996</link>
      <description>     As an information security professional I believe that the source of a companies IT controls is of extreme importance. As with any structure that is purpose built and meant to stand the test of time, serious consideration must be put into it's</description>
      <pubDate>Tue, 17 Nov 2009 01:57:06 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/1996?tstart=0#1996</guid>
      <dc:date>2009-11-17T01:57:06Z</dc:date>
      <clearspace:dateToText>4 days, 8 hours ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Where Do I Get My Controls?</title>
      <link>http://www.itbusinessedge.com/cm/message/1995?tstart=0#1995</link>
      <description>Yes. Today the main driver of security practices are usually led by some regulatory compliance requirement. This is not to say that companies are not concerned with overall general security like ensuring their environment is meeting an internally driven</description>
      <pubDate>Mon, 16 Nov 2009 13:39:08 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/1995?tstart=0#1995</guid>
      <dc:date>2009-11-16T13:39:08Z</dc:date>
      <clearspace:dateToText>4 days, 20 hours ago</clearspace:dateToText>
      <clearspace:replyCount>4</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Identifying Security Threats</title>
      <link>http://www.itbusinessedge.com/cm/message/1994?tstart=0#1994</link>
      <description>I agree that an infinite amount of time can be spent identifying every possible threat and creating boundaries is a nice way to manage time when brainstorming these threats.  I understand that some threats that people may think of have a very unlikely</description>
      <pubDate>Sat, 14 Nov 2009 15:27:17 GMT</pubDate>
      <author>webadmin@itbusinessedge.com</author>
      <guid>http://www.itbusinessedge.com/cm/message/1994?tstart=0#1994</guid>
      <dc:date>2009-11-14T15:27:17Z</dc:date>
      <clearspace:dateToText>6 days, 19 hours ago</clearspace:dateToText>
    </item>
  </channel>
</rss>

