<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>InfoSecMinds &#187; Information Security Risk Assessment</title>
	<atom:link href="http://infosecminds.com/tag/information-security-risk-assessment/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecminds.com</link>
	<description>For like-minded people</description>
	<lastBuildDate>Wed, 05 May 2010 07:29:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Service Asset – A Requirement or Duplication</title>
		<link>http://infosecminds.com/2009/07/05/service-asset-%e2%80%93-a-requirement-or-duplication/</link>
		<comments>http://infosecminds.com/2009/07/05/service-asset-%e2%80%93-a-requirement-or-duplication/#comments</comments>
		<pubDate>Sun, 05 Jul 2009 11:35:42 +0000</pubDate>
		<dc:creator>Vinod Puthuseeri</dc:creator>
				<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001:2005]]></category>
		<category><![CDATA[Information Security Risk Assessment]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Asset Identificaion]]></category>
		<category><![CDATA[Asset Inventory]]></category>

		<guid isPermaLink="false">http://infosecminds.com/?p=125</guid>
		<description><![CDATA[It just came up recently while discussing with one of my friend, the need for capturing service assets as a part of asset inventory which will be used further for risk assessment exercise. In a normal scenario, everyone uses a template that captures assests under different cateogories, viz Information Asset – deals with electronic and [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:justify;">It just came up recently while discussing with one of my friend, the need for capturing service assets as a part of asset inventory which will be used further for risk assessment exercise.</p>
<p style="text-align:justify;">In a normal scenario, everyone uses a template that captures assests under different cateogories, viz</p>
<ul style="text-align:justify;">
<li>Information Asset – deals with electronic and paper based data</li>
<li>Hardware Asset – includes all your hardware, cupboards, safe, etc</li>
<li>Software Asset – includes all software’s used or implemented in the organization.</li>
<li>Service Asset – services that a department avails from the organization</li>
<li>People Asset – talks about people / employees</li>
</ul>
<p style="text-align:justify;"> Now the discussion went like this:</p>
<p style="text-align:justify;"><span id="more-125"></span></p>
<p style="text-align:justify;"> We capture service assets and also get the availability value of that asset from each department to determine the asset value. Now, a disruption in service is caused to one or more of the following:</p>
<ul style="text-align:justify;">
<li>A failure of hardware</li>
<li>A failure of software</li>
<li>A failure of people</li>
</ul>
<p style="text-align:justify;">One or more of the above failures will cause a service disruption and we are already capturing the availability values of these parameters under hardware asset, software asset and people asset respectively.</p>
<p style="text-align:justify;">The question arise was is it not a duplication of effort and capturing of availability value in the above case. If yes, why do we do this?</p>
<p style="text-align:justify;">Now in security perspective:</p>
<ol style="text-align:justify;">
<li>Hardware is identified / recorded only if the end user has a direct interaction wit that server. For example: File Server</li>
<li>If it is a service availed by the end user, he/she is unaware of hardware that is used for providing that service. Hence he will only term that as an service and will not be captured as a part of hardware asset.</li>
<li>When it comes to the IT department, they will identify all the hardware that is available under their control. Now they will identify the hardware, but will be unable to determine the availability parameter of the service provided through that hardware from a business perspective.</li>
</ol>
<p style="text-align:justify;">Hence it is required to capture the service assets from various departments while we carry out a function based risk assessment exercise.</p>
<p style="text-align:justify;">Further, it is not only about failures that are looked into while capturing the service assets. As a part of the control recommendations, based on the inputs from various user departments, it could also be possible that the recommendation will be to provide the service on a fail over module or utilize and load balancer etc.</p>
<p style="text-align:justify;">Now, looking at the other aspect of capturing service assets would be to understand the services availed from the organization, where, the organization has procured it from a third party. For example: An internet connection from the ISP.</p>
<p style="text-align:justify;">We will not be capturing the hardware, software or people asset outside our organization, but still will be using a particular service. There might be one piece of asset that is connecting between the organization and the ISP, but after that we have no controls. Hence we will require to capture the service assets which will help in defining SLA’s with the vendors and procure adequate service.</p>
<p style="text-align:justify;"> Looking forward for your thoughts.</p>
]]></content:encoded>
			<wfw:commentRss>http://infosecminds.com/2009/07/05/service-asset-%e2%80%93-a-requirement-or-duplication/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>ISMS Implementation Guide</title>
		<link>http://infosecminds.com/2007/04/04/isms-implementation-guide/</link>
		<comments>http://infosecminds.com/2007/04/04/isms-implementation-guide/#comments</comments>
		<pubDate>Wed, 04 Apr 2007 08:43:58 +0000</pubDate>
		<dc:creator>Vinod Puthuseeri</dc:creator>
				<category><![CDATA[ISO 27001:2005]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Security Management System]]></category>
		<category><![CDATA[Information Security Risk Assessment]]></category>

		<guid isPermaLink="false">http://infosecminds.com/?p=16</guid>
		<description><![CDATA[ISMS Implementation Guide is one of my first white papers which was written out of my personal experience in implementing Information Security practices in an organization using the BS ISO/IEC 17799:2005 framework. This paper is intended to give an insight and help, those who are implementing this for the first time and for those who [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:justify;">ISMS Implementation Guide is one of my first white papers which was written out of my personal experience in implementing Information Security practices in an organization using the BS ISO/IEC 17799:2005 framework. This paper is intended to give an insight and help, those who are implementing this for the first time and for those who will be coordinating with external consultants for ISMS implementations in their organizations.</p>
<p>Please download the document here:<br />
<a href="http://vputhuseeri.files.wordpress.com/2008/07/isms_implementation_guide.pdf">ISMS Implementation Guide</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infosecminds.com/2007/04/04/isms-implementation-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
