<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.ism-community.org/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Policies And Standards Blog</title><subtitle type="html" /><id>http://www.ism-community.org/blogs/policiesandstandardsblog/atom.aspx</id><link rel="alternate" type="text/html" href="http://www.ism-community.org/blogs/policiesandstandardsblog/default.aspx" /><link rel="self" type="application/atom+xml" href="http://www.ism-community.org/blogs/policiesandstandardsblog/atom.aspx" /><generator uri="http://communityserver.org" version="3.0.20423.869">Community Server</generator><updated>2007-04-27T20:20:59Z</updated><entry><title>New Project Leader for Policies and Standards Focus Area</title><link rel="alternate" type="text/html" href="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/08/new-project-leader-for-policies-and-standards-focus-area.aspx" /><id>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/08/new-project-leader-for-policies-and-standards-focus-area.aspx</id><published>2007-06-08T12:41:01Z</published><updated>2007-06-08T12:41:01Z</updated><content type="html">&lt;p&gt;&lt;/p&gt; &lt;p&gt;Ciske van Oosten has agreed to take over the Policies and Standards project at the ISM Community. Ciske runs a great blog focused on policies and standards at &lt;a href="http://infosec-risk.blogspot.com/"&gt;http://infosec-risk.blogspot.com/&lt;/a&gt;.  &lt;p&gt;The idea behind the Policies and Standards project is to build and maintain a comprehensive and well written free set of policies and standards. These things are rarely competitive advantages to any company and so collaboration can benefit everyone. There are some documents now floating around as donations from various companies which is also great.  &lt;p&gt;Ciske has written a great guide to policies and standards and has some great ideas and passion to make this project happen. &lt;p&gt;The discussion forum is here &lt;a href="http://www.ism-community.org/forums/68.aspx"&gt;http://www.ism-community.org/forums/68.aspx&lt;/a&gt; and I am sure Ciske will be sending some updates and have a project plan via the ISM blog for the project here &lt;a href="http://www.ism-community.org/focusareas/21/PoliciesAndStandardsBlog/focusarea.aspx"&gt;http://www.ism-community.org/focusareas/21/PoliciesAndStandardsBlog/focusarea.aspx&lt;/a&gt; &lt;p&gt;If you have any policies and standards you would donated as baseline documents please contact Ciske via the forums.  &lt;p&gt;Cheers, &lt;p&gt;Mark&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=958" width="1" height="1"&gt;</content><author><name>mcurphey</name><uri>http://www.ism-community.org/members/mcurphey.aspx</uri></author><category term="ProjectNews" scheme="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/tags/ProjectNews/default.aspx" /></entry><entry><title>ISM Community Top Ten - Draft</title><link rel="alternate" type="text/html" href="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/04/ism-community-top-ten-draft.aspx" /><id>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/04/ism-community-top-ten-draft.aspx</id><published>2007-06-04T14:43:48Z</published><updated>2007-06-04T14:43:48Z</updated><content type="html">&lt;p&gt;I have just uploaded the ISM Community Top Ten Draft &lt;a href="http://www.ism-community.org/files/folders/trainingandawarenessrelease/entry946.aspx"&gt;here&lt;/a&gt;. The intention of the T10 is to provide a short and concise awareness document. In the same genre as the SANS Top 20 and OWASP Top Ten it can be used by business managers as well as information security professionals to&amp;nbsp;provoke thought about&amp;nbsp;their current information security programs. &lt;/p&gt; &lt;p&gt;We plan to release the final&amp;nbsp;document next week. There have been several volunteers who have kindly offered to translate it into other languages. The current draft requires some final touches and if anyone has some time today or tomorrow please download it, edit it with tracking turned on (important) and email it to me (mark at curphey dot com). &lt;/p&gt; &lt;p&gt;What is required is;&lt;/p&gt; &lt;p&gt;1. Proof reading (grammar, accuracy and completeness)&lt;/p&gt; &lt;p&gt;2. Tips and Tricks from the field added to sections 8, 9 and 10&lt;/p&gt; &lt;p&gt;Any major changes we can consider for an updated version later this year.&lt;/p&gt; &lt;p&gt;Cheers.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=947" width="1" height="1"&gt;</content><author><name>mcurphey</name><uri>http://www.ism-community.org/members/mcurphey.aspx</uri></author><category term="ProjectNews" scheme="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/tags/ProjectNews/default.aspx" /></entry><entry><title>Policies and Standards -Week Deux</title><link rel="alternate" type="text/html" href="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/05/10/policies-and-standards-week-deux.aspx" /><id>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/05/10/policies-and-standards-week-deux.aspx</id><published>2007-05-10T14:33:14Z</published><updated>2007-05-10T14:33:14Z</updated><content type="html">&lt;p&gt;The summer is finally here in the South of France. Its 86 today and from this point until the end of Sept it should be sunny and hot.&lt;/p&gt; &lt;p&gt;We had a few offers for some policy documents but sadly most had strings attached that meant they would not be suitable for everyone to consume so it looks like well just need to start from the ground up. &lt;/p&gt; &lt;p&gt;My plan is as follows.&lt;/p&gt; &lt;p&gt;This week: review a stack of links I have to whitepapers, blogs etc&amp;nbsp;about policies and standards and summarize them along with some notes. From this we can then create a plan that solves the problems and develop a list of tasks. &lt;/p&gt; &lt;p&gt;Anyone volunteer to help me write some content?&lt;/p&gt; &lt;p&gt;Jason made some interesting points about writing policies and cited his blog. &lt;/p&gt; &lt;p&gt;&lt;a href="http://infosecalways.com/2007/05/08/roles-responsibilities-in-policy/"&gt;http://infosecalways.com/2007/05/08/roles-responsibilities-in-policy/&lt;/a&gt;&lt;/p&gt; &lt;p&gt;From the comments in his blog it seems there is some interest in defining roles and responsibilities in Information Security. &lt;/p&gt; &lt;p&gt;I have so much going on I forgot to post this and ask for a volunteer to get this idea off the ground. How about if we created an org chart of a few typical security departs (reporting up through the CIO, through legal and compliance, via another route etc) and defined a set of roles and responsibilities for the actors. I think this would be a valuable resource for many reasons. Any volunteers? I have a user persona template form which to start and I&amp;#39;ll buy you as much beer as you can drink in a 24 hour sitting!&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=899" width="1" height="1"&gt;</content><author><name>mcurphey</name><uri>http://www.ism-community.org/members/mcurphey.aspx</uri></author></entry><entry><title>Welcome to the Policies and Standards Focus Area</title><link rel="alternate" type="text/html" href="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/04/27/welcome-to-the-policies-and-standards-focus-area.aspx" /><id>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/04/27/welcome-to-the-policies-and-standards-focus-area.aspx</id><published>2007-04-27T18:20:59Z</published><updated>2007-04-27T18:20:59Z</updated><content type="html">&lt;p&gt;Welcome to the Policies and Standards Focus Area.&amp;nbsp;I plan to blog post here weekly with&amp;nbsp;news of&amp;nbsp;progress for those that don&amp;#39;t want to delve into the forums / mailing lists. You can subscribe to these updates via RSS at the side bar.&lt;/p&gt; &lt;p&gt;The first project I want to start as part of this Focus Area is to build and release a complete set of policies and standards. Whilst we are doing it I want to analyze what is out there today; what works and what doesn&amp;#39;t, and then compile those findings&amp;nbsp;into a Guide to writing Better Policies and Standards for anyone who finds themselves writing there own.&lt;/p&gt; &lt;p&gt;Everyone needs Policies and Standards&amp;nbsp;yet I believe&amp;nbsp;in general there is significant room for improvement to make them more engaging and more effective. &lt;/p&gt; &lt;p&gt;The first few tasks to get this project off the ground are;&lt;/p&gt; &lt;p&gt;1. Analyze the current issues with P&amp;#39;s &amp;amp; S&amp;#39;s (&lt;a href="http://www.ism-community.org/forums/p/501/744.aspx#744"&gt;I just posted to the forums a second ago so please add your 2 cents worth ASAP&lt;/a&gt;)&lt;/p&gt; &lt;p&gt;2. Develop a template for a policy and standard. We will be able to use the glossary that Paul Zedeck is creating for standard definitions&amp;nbsp;and ensure consistency. &lt;/p&gt; &lt;p&gt;3. Develop and&amp;nbsp;maintain an &amp;quot;org chart like&amp;quot; Visio diagram of a reference hierarchy of policies and standards. &lt;/p&gt; &lt;p&gt;This &amp;quot;reference hierarchy&amp;quot; can then also serve as a task list and people can volunteer to write specific policies or standards and submit them for review.&lt;/p&gt; &lt;p&gt;The forums should start functioning like traditional mailing lists very soon and we have file storage areas in which to easily store our Word documents.&lt;/p&gt; &lt;p&gt;Of course it goes without saying that if any company would like to donate their policies and standards or anyone has anything which would make a solid base then please contact me. We can make sure there is nothing sensitive and or 100% anonymize them before they are placed online.&lt;/p&gt; &lt;p&gt;If you would like to volunteer to help please post to the forum. &lt;/p&gt; &lt;p&gt;&lt;a title="http://www.ism-community.org/forums/68.aspx" href="http://www.ism-community.org/forums/68.aspx"&gt;http://www.ism-community.org/forums/68.aspx&lt;/a&gt;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=741" width="1" height="1"&gt;</content><author><name>mcurphey</name><uri>http://www.ism-community.org/members/mcurphey.aspx</uri></author><category term="ProjectNews" scheme="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/tags/ProjectNews/default.aspx" /></entry></feed>