<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: gtags]]></title>
    <link>http://securityratty.com/tag/gtags</link>
    <description></description>
    <pubDate>Sat, 29 Dec 2007 02:09:20 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Art of Information Security Episode 002: GTAGs and Safe Harbors]]></title>
      <link>http://securityratty.com/article/26a2cfe1609480d7da2cedaf4ef214f4</link>
      <guid>http://securityratty.com/article/26a2cfe1609480d7da2cedaf4ef214f4</guid>
      <description><![CDATA[Art of Info Sec 002: GTAGs and Safe Harbors
GTAGs
The Institute of Internal Auditors has been releasing a white paper series on issues related to IT Risk Management and Information Security. The...]]></description>
      <content:encoded><![CDATA[<p><a href="http://artofinfosec.com/wp-content/uploads/2007/12/aois-002-gtags-and-safe-harbors.m4a" title="Art of Info Sec 002: GTAGs and Safe Harbors" >Art of Info Sec 002: GTAGs and Safe Harbors</a></p>
<p><strong>GTAG&#8217;s</strong></p>
<p><a href="http://www.theiia.org" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.theiia.org');">The Institute of Internal Auditors</a> has been releasing a white paper series on issues related to IT Risk Management and Information Security. The paper&#8217;s are titled as GTAGs, which is an acronym for <a href="http://www.theiia.org/guidance/technology/gtag/" title="GTAG Landing Page" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.theiia.org/guidance/technology/gtag/');">Global Technology Audit Guidance</a>. The project is very ambitious, trying to break down major technical topics, the IT risks associated with them, and the controls that are available in a concise format accessible to senior risk executives.</p>
<p>Of the nine that have been released to date, several caught my eye. Here are the ones I would like to highlight:</p>
<ul>
<li>Auditing Application Controls</li>
<li>Change and Patch Management Controls</li>
<li>Identity and Access Management</li>
<li>Information Technology Outsourcing</li>
<li>Managing and Auditing Privacy Risks</li>
<li>Managing and Auditing IT Vulnerabilities</li>
</ul>
<p>You can find the library of papers at  <a href="http://www.theiia.org/guidance/technology/gtag/" target="_blank" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.theiia.org/guidance/technology/gtag/');">The IIA&#8217;s GTAG portal</a>. New materials are released regularly.</p>
<p><strong>In Other News&#8230; </strong></p>
<p>Earlier this month I participated in a Webinar titled <a href="http://http://www.venafi.com/replays/webinar120507/" title="Webinar Link" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://http://www.venafi.com/replays/webinar120507/');">&#8220;Getting More Encryption for Less&#8221;</a>. At the end of the call there were a few interesting questions during the Q and A session, one of which I wanted to recap here&#8230;</p>
<p>Question: Will Federal Privacy Regulations include Cryptography Standards for &#8220;Safe Harbors&#8221; ?</p>
<ul>
<li>Discuss what a Safe Harbor is, using California Security Breach Information Act (SB-1386) as an example</li>
<li>Introduce <a href="http://csrc.nist.gov/" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://csrc.nist.gov/');">NIST</a>, <a href="http://http://en.wikipedia.org/wiki/Federal_Information_Processing_Standard" target="_blank" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://http://en.wikipedia.org/wiki/Federal_Information_Processing_Standard');">FIPS</a>, and  <a href="http://en.wikipedia.org/wiki/FIPS_140-2" target="_blank" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://en.wikipedia.org/wiki/FIPS_140-2');">FIPS 140-2</a></li>
</ul>
<p>Cheers, Erik</p>
<p><a href="http://artofinfosec.com" >Art of Information Security</a> would <a href="http://artofinfosec.com/feedback/" >love your feedback</a> !</p>
<p><a href="http://artofinfosec.com/4/art-of-information-security-episode-002-gtags-and-safe-harbors/" >Art of Information Security Episode 002: GTAGs and Safe Harbors</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/207882937" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 29 Dec 2007 02:09:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security episode">information security episode</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/safe harbors">safe harbors</category>
      <category domain="http://securityratty.com/tag/gtags">gtags</category>
      <category domain="http://securityratty.com/tag/controls">controls</category>
      <category domain="http://securityratty.com/tag/application controls">application controls</category>
      <category domain="http://securityratty.com/tag/art">art</category>
      <category domain="http://securityratty.com/tag/patch management controls">patch management controls</category>
      <category domain="http://securityratty.com/tag/concise format accessible">concise format accessible</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/207882937/">Art of Information Security Episode 002: GTAGs and Safe Harbors</source>
    </item>
  </channel>
</rss>
