SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> No Category

Time for Information Security Management to Go to War

Time for Information Security Management to Go to War

By:  Dan Swanson  On: 30 Apr 2000 For: CIO Canada Creator

Sun Tzu's The Art of War has long been required reading for military leaders. Andrew Clark has taken this masterpiece of war-fighting strategy and built an inspiring corollary that draws on the techniques and motives of the war-fighter and places them in the information warfare arena. This innovative document may change the way you view your information technology defensive posture.

The concluding section is particularly thought-provoking, as can be seen from the following quote: "Today, many of us in the field of information security are expected to fill the role of general in the event of conflict. Few of us have felt the need to study the art of war -- perhaps it is time to change that."

Practices for Securing Critical Information Systems is a very comprehensive report recently produced by the Critical Infrastructure Assurance Office (CIAO). The document details the processes for locking down components of your information technology infrastructure. It provides guidance for the development of an effective computer security program and delineates the interrelationships of the individual components. This document represents a "total defence" approach to computer security and is a "must have" for your computer security library.

I also like the extensive hypertext links and pointers to information created and maintained by other leading public and private organizations. Just applying the ideas from the report's Appendix E -- Low-cost/No-cost Computer Security Measures -- will greatly increase your organization's security effectiveness.

The two reports (and many others) are available at http://www.fedcirc.gov/docsindex.html.

Leading Web Sites Supporting Security Management

1. ISSA -- Information Systems Security Association

www.issa.org

2. COAST -- Computer Operations, Audit and Security Technology

www.cs.purdue.edu/coast

3. CERT -- Computer Emergency Response Team

www.cert.org

4. CSI -- Computer Security Institute

www.gocsi.com

5. ICSA -- International Computer Security Association (formerly NCSA)

www.icsa.net

6. NIST -- National Institute of Standards and Technology

www.nist.gov

7. FEDCIRC -- Federal Computer Incident Response Capability

www.fedcirc.gov

Dan Swanson is a management consultant with LGS Group in Winnipeg. He specializes in audit and management consulting and can be reached at dswanson@lgs.ca


Sign up for our Newsletters












Print |  Views: 355   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Dan Swanson Dan Swanson is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Making a play for the infrastructure
Making a play for the infrastructureSymantec Corp. wants more presence in the enterprise IT infrastructure space and its spate of acquisitions and technology strategies are evidence of that move. ComputerWorld Canada senior writer Mari-Len De Guzman recently sat down with CEO and chairman John Thompson to explore that aspect of his company’s business and more
Survey reveals unexpected drop in insider attacks
Survey reveals unexpected drop in insider attacksSome experts are questioning recent findings that defy the conventional wisdom that insiders constitute the primary threat to enterprise security.
Insider threats hard to detect
Insider threats hard to detectRecent findings that insiders constitute the primary threat to enterprise security are being challenged by experts who insist the greater threat to security remains external.
Some sober second thoughts on 2008 IT predictions
the new year always starts with a bang of predictions on what’s hot and what’s not. most of these predictions are just more hype to get you going with some new technologies or get some more zip into your conversations. the best list of predictions i have seen for 2008 is the in the mckinsey quarterly, january 9, 2007 entitled ‘eight
Does Virtualization Equal ‘Bullet Proof’?
virtualization has been available to the it world for more than four decades, yet it has still not really taken off in the multi system environment.  many vendors are pushing this approach to deploying ‘flexible technology’, yet it still has not emerged beyond the ‘glass house’ of the data centers or server closets.  ibm i
Copyright past, copyright present, copyright future, and election 2008
on october 1’st i was invited by the waterloo public interest research group (wpirg) and the waterloo students for the information commons (wsic) to the university of waterloo to give a talk on copyright and bill c-61. the outline for this message is the sa

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.