|
Document Repository with outlines and guides to compliment Monthly webinar series. Webinar series includes:
- Defining Security
- Risk
- Controls
- Regulations and Compliance
- Who needs to be Compliant?
- What do we need to be compliant about?
i. Privacy
ii. Gramm-Leach-Bliley
iii. HIPAA
iv. Sarbanes-Oaxley
v. PCI-DSS
- Identifying Risks
- Internal
- External
- Natural
- Manmade
- Building an Information Security Plan
- Employees and HR Issues
- Access Controls
- Data Access and Classification
- Procedural Controls
- Technical Controls
- Physical Security
- Network Perimeters
- Endpoint Protection
- Remote Access Issues
- Addressing Data Leakage
- Audits and Testing
- Backups
- Social Engineering
- End User Training
- Building an Incident Response Plan
- Identifying Likely Threats and Scenarios
- Establishing Priorities
- Containment and Isolation
- Collection of Evidence
- Involvement of Law Enforcement
- Building a Disaster Recovery Plan
- Talking about Scope
i. Small-scale (hardware failures)
ii. Local (tornados, sinkholes, riots,etc)
iii. Regional (Hurricanes, Earthquakes, etc)
iv. National/Global (pandemics)
-
- Personnel
- Identifying the Business Needs
- Setting Expectations and Budget
- Advance Planning
- Testing the Plan
- Example scenarios
i. Fire in Server Room
ii. Tornado destroys building
iii. Hurricane devastates region
iv. Disease Epidemic or Pandemic
v. Just for fun: Zombie Outbreak
|