TOPIC 1 : INTRODUCTION TO SECURITY MANAGEMENT
por AIDIEL RAHMAN__
1. best practice information security
1.1. security policies
1.2. end user acceptable use guidelines
1.3. vendor mangment
1.4. physical security
1.5. password requirements and guidelines
1.6. wireless networking
1.7. employee awareness training
2. organization principle
2.1. logical division work
2.2. clear lines of authority & responsibility
2.3. unity of command
2.4. responsibility , authority & accountability
2.5. span of control
3. education and awareness in the organization
3.1. The Risk of Poor Information Security Management
3.1.1. Without policies and security-management controls in place, the organization is really saying that anything goes. That opens the organization to a host of risks, both internal and external
3.1.2. example:
3.1.2.1. internal threat
3.1.2.1.1. leakage of sensitive data
3.1.2.1.2. theft
3.1.2.1.3. legal liability
3.1.2.1.4. corruption of data
3.1.3. external threat
3.1.3.1. natural disasters
3.1.3.2. spyware
3.1.3.3. viruses
3.1.3.4. worms
3.1.3.5. Trojan programs