<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.ism-community.org/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Policies And Standards Blog : ProjectNews</title><link>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/tags/ProjectNews/default.aspx</link><description>Tags: ProjectNews</description><dc:language>en</dc:language><generator>CommunityServer 2007 (Build: 20423.869)</generator><item><title>New Project Leader for Policies and Standards Focus Area</title><link>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/08/new-project-leader-for-policies-and-standards-focus-area.aspx</link><pubDate>Fri, 08 Jun 2007 12:41:01 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:958</guid><dc:creator>mcurphey</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.ism-community.org/blogs/policiesandstandardsblog/rsscomments.aspx?PostID=958</wfw:commentRss><comments>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/08/new-project-leader-for-policies-and-standards-focus-area.aspx#comments</comments><description>&lt;p&gt;&lt;/p&gt; &lt;p&gt;Ciske van Oosten has agreed to take over the Policies and Standards project at the ISM Community. Ciske runs a great blog focused on policies and standards at &lt;a href="http://infosec-risk.blogspot.com/"&gt;http://infosec-risk.blogspot.com/&lt;/a&gt;.  &lt;p&gt;The idea behind the Policies and Standards project is to build and maintain a comprehensive and well written free set of policies and standards. These things are rarely competitive advantages to any company and so collaboration can benefit everyone. There are some documents now floating around as donations from various companies which is also great.  &lt;p&gt;Ciske has written a great guide to policies and standards and has some great ideas and passion to make this project happen. &lt;p&gt;The discussion forum is here &lt;a href="http://www.ism-community.org/forums/68.aspx"&gt;http://www.ism-community.org/forums/68.aspx&lt;/a&gt; and I am sure Ciske will be sending some updates and have a project plan via the ISM blog for the project here &lt;a href="http://www.ism-community.org/focusareas/21/PoliciesAndStandardsBlog/focusarea.aspx"&gt;http://www.ism-community.org/focusareas/21/PoliciesAndStandardsBlog/focusarea.aspx&lt;/a&gt; &lt;p&gt;If you have any policies and standards you would donated as baseline documents please contact Ciske via the forums.  &lt;p&gt;Cheers, &lt;p&gt;Mark&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=958" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/tags/ProjectNews/default.aspx">ProjectNews</category></item><item><title>ISM Community Top Ten - Draft</title><link>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/04/ism-community-top-ten-draft.aspx</link><pubDate>Mon, 04 Jun 2007 14:43:48 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:947</guid><dc:creator>mcurphey</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.ism-community.org/blogs/policiesandstandardsblog/rsscomments.aspx?PostID=947</wfw:commentRss><comments>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/04/ism-community-top-ten-draft.aspx#comments</comments><description>&lt;p&gt;I have just uploaded the ISM Community Top Ten Draft &lt;a href="http://www.ism-community.org/files/folders/trainingandawarenessrelease/entry946.aspx"&gt;here&lt;/a&gt;. The intention of the T10 is to provide a short and concise awareness document. In the same genre as the SANS Top 20 and OWASP Top Ten it can be used by business managers as well as information security professionals to&amp;nbsp;provoke thought about&amp;nbsp;their current information security programs. &lt;/p&gt; &lt;p&gt;We plan to release the final&amp;nbsp;document next week. There have been several volunteers who have kindly offered to translate it into other languages. The current draft requires some final touches and if anyone has some time today or tomorrow please download it, edit it with tracking turned on (important) and email it to me (mark at curphey dot com). &lt;/p&gt; &lt;p&gt;What is required is;&lt;/p&gt; &lt;p&gt;1. Proof reading (grammar, accuracy and completeness)&lt;/p&gt; &lt;p&gt;2. Tips and Tricks from the field added to sections 8, 9 and 10&lt;/p&gt; &lt;p&gt;Any major changes we can consider for an updated version later this year.&lt;/p&gt; &lt;p&gt;Cheers.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=947" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/tags/ProjectNews/default.aspx">ProjectNews</category></item><item><title>Welcome to the Policies and Standards Focus Area</title><link>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/04/27/welcome-to-the-policies-and-standards-focus-area.aspx</link><pubDate>Fri, 27 Apr 2007 18:20:59 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:741</guid><dc:creator>mcurphey</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.ism-community.org/blogs/policiesandstandardsblog/rsscomments.aspx?PostID=741</wfw:commentRss><comments>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/04/27/welcome-to-the-policies-and-standards-focus-area.aspx#comments</comments><description>&lt;p&gt;Welcome to the Policies and Standards Focus Area.&amp;nbsp;I plan to blog post here weekly with&amp;nbsp;news of&amp;nbsp;progress for those that don&amp;#39;t want to delve into the forums / mailing lists. You can subscribe to these updates via RSS at the side bar.&lt;/p&gt; &lt;p&gt;The first project I want to start as part of this Focus Area is to build and release a complete set of policies and standards. Whilst we are doing it I want to analyze what is out there today; what works and what doesn&amp;#39;t, and then compile those findings&amp;nbsp;into a Guide to writing Better Policies and Standards for anyone who finds themselves writing there own.&lt;/p&gt; &lt;p&gt;Everyone needs Policies and Standards&amp;nbsp;yet I believe&amp;nbsp;in general there is significant room for improvement to make them more engaging and more effective. &lt;/p&gt; &lt;p&gt;The first few tasks to get this project off the ground are;&lt;/p&gt; &lt;p&gt;1. Analyze the current issues with P&amp;#39;s &amp;amp; S&amp;#39;s (&lt;a href="http://www.ism-community.org/forums/p/501/744.aspx#744"&gt;I just posted to the forums a second ago so please add your 2 cents worth ASAP&lt;/a&gt;)&lt;/p&gt; &lt;p&gt;2. Develop a template for a policy and standard. We will be able to use the glossary that Paul Zedeck is creating for standard definitions&amp;nbsp;and ensure consistency. &lt;/p&gt; &lt;p&gt;3. Develop and&amp;nbsp;maintain an &amp;quot;org chart like&amp;quot; Visio diagram of a reference hierarchy of policies and standards. &lt;/p&gt; &lt;p&gt;This &amp;quot;reference hierarchy&amp;quot; can then also serve as a task list and people can volunteer to write specific policies or standards and submit them for review.&lt;/p&gt; &lt;p&gt;The forums should start functioning like traditional mailing lists very soon and we have file storage areas in which to easily store our Word documents.&lt;/p&gt; &lt;p&gt;Of course it goes without saying that if any company would like to donate their policies and standards or anyone has anything which would make a solid base then please contact me. We can make sure there is nothing sensitive and or 100% anonymize them before they are placed online.&lt;/p&gt; &lt;p&gt;If you would like to volunteer to help please post to the forum. &lt;/p&gt; &lt;p&gt;&lt;a title="http://www.ism-community.org/forums/68.aspx" href="http://www.ism-community.org/forums/68.aspx"&gt;http://www.ism-community.org/forums/68.aspx&lt;/a&gt;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=741" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/tags/ProjectNews/default.aspx">ProjectNews</category></item></channel></rss>