03/28/2012 | Security Strategy
Security awareness training is a topic that never goes out of favor with IANS clients. Because our environments and the threats to them are always changing, information security teams must look for new, fresh ways to keep users engaged, knowledgeable, and prepared for an incident. In this document, Mike Saurbaugh offers some practical advice for security teams looking to improve
11/17/2011 | Security Strategy
Incident response is a process with which all IANS clients and delegates are familiar. Every company has a plan. Every information security professional has dealt with an incident in some form or fashion. All too often, though, IANS Faculty finds that groups have a standard incident response that may or may not be up-to-date. In many cases, legacy is the precedent for response.
09/14/2011 | Security Strategy
The security problem has never been more obvious yet the investment in security start ups remains anemic. Venture Capital firms are in a corrective state as are many corporations driving them to cut costs (i.e., security budgets), never mind the global economy's pervasive overhang. As such, the barriers to entry for any aspiring hacker are not being reinforced while the cost to
08/24/2011 | Security Strategy
Adding information security elements to corporate contracts can be tricky and confusing, especially if you don’t have all the right constituencies involved. Join IANS Faculty Jeffrey Ritter as he presents five key strategies for addressing security in your commercial contracts. Participants will learn best practices for improving team collaboration, receive a detailed strategic
08/10/2011 | Security Strategy
With any number of constituents clamoring to ensure their key issues are covered, the contracting process can be difficult and arduous. The complexity of the negotiation process is small comfort, though, when a problem occurs and fingers are pointed at security and risk teams. To be able to solve the problem of baking security into the contracting process, it’s important to
06/21/2011 | Security Strategy
These examples are based on conversations with IANS clients getting started with building a matrix of controls and services to present to senior management. They’re interested in proving the business value of their security activities in a scalable and simple way. IANS Faculty Member Diana Kelley offers tips on building and using a matrix and improving communication between
06/20/2011 | Security Strategy
This IANS client is getting started with building a matrix of controls and services to present to senior management. They’re interested in proving the business value of their security activities in a scalable and simple way. IANS offers tips on building and using a matrix and improving communication between information security and the executive team.
05/26/2011 | Security Strategy
The IANS Security Program Maturity study found some important trends among IT managers. This organization-wide look at the maturity of security programs showed some positive trends in the areas of planning and standards and budgets. Across different corporate segments, managers are generally using strategic plans and objectives to further their goals. Strategic plans and
02/28/2010 | Security Strategy
For the past eight years, IANS has moderated discussions with CISOs and security leaders around how to build, manage and motivate strong information security teams. Business writers have forever tried to capture the key elements of high-performing teams in general. IANS has taken the high points of this body of research and applied them to the information security profession to
08/28/2009 | Security Strategy
Determine how organizations are approaching the growing use of personal devices, social networking and cloud-based technologies in the workplace. More specifically, what decisions are organizations struggling with regarding their use for both business and personal purposes? This is in light of the increasing grey area in blended lifestyles (e.g., the convergence of personal and