<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Quality News &#187; security</title>
	<atom:link href="http://quality-news.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://quality-news.com</link>
	<description>News about ISO standards and Quality Management</description>
	<lastBuildDate>Wed, 09 May 2012 09:05:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Guidelines for auditors on information security controls</title>
		<link>http://quality-news.com/1644/guidelines-for-auditors-on-information-security-controls/</link>
		<comments>http://quality-news.com/1644/guidelines-for-auditors-on-information-security-controls/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 08:25:41 +0000</pubDate>
		<dc:creator>QualityEditor</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[ISO Standards]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[ISO STANDARD]]></category>
		<category><![CDATA[Quality]]></category>
		<category><![CDATA[Quality control]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=1644</guid>
		<description><![CDATA[An ISO/IEC technical report (TR) providing technical controls and compliance guidelines for auditors can improve the effectiveness of an organization’s information security system. ISO/IEC TR 27008:2011, Information technology – Security techniques – Guidelines for auditors on information security controls, aims to instill confidence in the controls underpinning an organization’s information security management system. The review [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_1645" class="wp-caption alignleft" style="width: 145px"><a href="http://quality-news.com/wp-content/uploads/2011/11/Information-Security_0.jpg"><img src="http://quality-news.com/wp-content/uploads/2011/11/Information-Security_0.jpg" alt="Information security controls" width="135" height="110" /></a><p class="wp-caption-text">Information security controls</p></div>
<p><strong>An ISO/IEC</strong> technical report (TR) providing technical controls and compliance guidelines for auditors can improve the effectiveness of an organization’s information security system.</p>
<p><strong>ISO/IEC TR 27008:2011</strong>, Information technology – Security techniques – Guidelines for auditors on information security controls, aims to instill confidence in the controls underpinning an organization’s information security management system. The review applies to all parts of the organization, including business processes and its information systems environment.</p>
<p><strong>“The business environment is constantly changing – along with threats to a company’s survival</strong>.<strong> Organizations</strong></p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 336x280, Ajdin */
google_ad_slot = "2018513310";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p><strong>need to be ahead of the game, and an excellent defence can be built around audit of the controls used to support the information security,”</strong> says <strong>Edward Humphreys,</strong> leader of the working group that developed the new document.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
<strong>“ISO/IEC TR 27008:2011</strong> supports a rigorous organizational security audit and review programme for information security controls, to enable the organization to have confidence that their controls have been appropriately implemented and operated and that their information security is ‘fit for purpose’.”</p>
<p><strong>ISO/IEC 27008</strong> provides guidance on reviewing the implementation and operation of controls, including technical compliance checking. The document is principally aimed at information security auditors who need to check the technical compliance of an organization’s information security controls against<strong> ISO/IEC 27002</strong> and any other control standards used by the organization.<strong> ISO/IEC TR 27008</strong> will help them to:</p>
<p><strong>- Identify and understand the extent of potential problems and shortfalls of information security controls</strong><br />
<strong>- Identify and understand the potential organizational impacts of inadequately mitigated information security threats and vulnerabilities</strong><br />
<strong> &#8211; Prioritize information security risk mitigation activities</strong><br />
<strong> &#8211; Confirm that previously identified or emergent weaknesses or deficiencies have been adequately addressed</strong><br />
<strong> &#8211; Support budgetary decisions within the investment process and other management decisions relating to improvement of organization’s information security management.</strong></p>
<p>&nbsp;</p>
<p>Read more text <a href="http://www.iso.org">http://www.iso.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/1644/guidelines-for-auditors-on-information-security-controls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Road vehicles – Pedestrian protection ISO 11096:2011</title>
		<link>http://quality-news.com/1609/road-vehicles-%e2%80%93-pedestrian-protection-iso-110962011/</link>
		<comments>http://quality-news.com/1609/road-vehicles-%e2%80%93-pedestrian-protection-iso-110962011/#comments</comments>
		<pubDate>Wed, 26 Oct 2011 10:19:55 +0000</pubDate>
		<dc:creator>QualityEditor</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[ISO Standards]]></category>
		<category><![CDATA[Quality management]]></category>
		<category><![CDATA[Quality tools]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[ISO 11096]]></category>
		<category><![CDATA[ISO STANDARD]]></category>
		<category><![CDATA[Quality Assurance]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=1609</guid>
		<description><![CDATA[The number of pedestrian leg injuries caused by dangerous car design should be reduced thanks to an ISO International Standard defining a new crash test method. According to the World Health Organization, road traffic accidents kill more than one million people a year, injuring another thirty-eight million (five million of them seriously). The death toll [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_1611" class="wp-caption alignleft" style="width: 148px"><a href="http://quality-news.com/wp-content/uploads/2011/10/pedestrian.gif"><img src="http://quality-news.com/wp-content/uploads/2011/10/pedestrian.gif" alt="Road vehicles – Pedestrian protection ISO 11096:2011" width="138" height="108" /></a><p class="wp-caption-text">Road vehicles – Pedestrian protection ISO 11096:2011</p></div>
<p>The number of pedestrian leg injuries caused by dangerous car design should be reduced thanks to an ISO International Standard defining a new crash test method.</p>
<p>According to the World Health Organization, road traffic accidents kill more than one million people a year, injuring another thirty-eight million (five million of them seriously). The death toll on the world&#8217;s roadways makes driving the number one cause of death and injury for people aged 15 to 44.</p>
<p><strong>ISO 11096:2011, Road vehicles – Pedestrian protection</strong> – Impact test method for pedestrian thigh, leg and knee, sets out a test method to assess the protection of an adult pedestrian by simulating the leg-impact conditions sustained during the car-to-pedestrian crash.</p>
<p><strong>The goal is two-fold – to:</strong></p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 336x280, Ajdin */
google_ad_slot = "2018513310";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p><strong>- Provide information on pedestrian safety to consumers</strong><br />
<strong> &#8211; Induce manufacturers to develop vehicles with excellent pedestrian protection.</strong></p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p><strong>Sukhbir Bilkhu</strong>, Chair of the ISO subcommittee that developed the standard, commented: “The pedestrian impact test simulates accidents in which a pedestrian is hit by an oncoming vehicle. These accidents represent about 15 % of fatal crashes.<strong> Thanks to ISO 11096</strong>, we will make substantial progress in improving vehicle structure, and in so doing, reducing pedestrian lower-limb injuries.”</p>
<p>&nbsp;</p>
<p>Read more text<a href="http://www.iso.org"> http://www.iso.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/1609/road-vehicles-%e2%80%93-pedestrian-protection-iso-110962011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO/IEC 27035:2011, Information technology – Security techniques – Information security incident management</title>
		<link>http://quality-news.com/1601/isoiec-270352011-information-technology-%e2%80%93-security-techniques-%e2%80%93-information-security-incident-management/</link>
		<comments>http://quality-news.com/1601/isoiec-270352011-information-technology-%e2%80%93-security-techniques-%e2%80%93-information-security-incident-management/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 07:08:00 +0000</pubDate>
		<dc:creator>QualityEditor</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[ISO Standards]]></category>
		<category><![CDATA[Quality control]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[ISO STANDARD]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[total quality management]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=1601</guid>
		<description><![CDATA[From hackers trying to break into networks, to insiders using their knowledge and internal access rights to use company data for their personal gain, the impact from a wide variety of information security threats can be reduced using an information security incident management approach contained in the new International Standard ISO/IEC 27035:2011. Information security breaches [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_1602" class="wp-caption alignleft" style="width: 145px"><a href="http://quality-news.com/wp-content/uploads/2011/10/securityrisk.jpg"><img src="http://quality-news.com/wp-content/uploads/2011/10/securityrisk.jpg" alt="Security techniques" width="135" height="110" /></a><p class="wp-caption-text">Security techniques</p></div>
<p>From hackers trying to break into networks, to insiders using their knowledge and internal access rights to use company data for their personal gain, the impact from a wide variety of information security threats can be reduced using an information security incident management approach contained in the new International Standard <strong>ISO/IEC 27035:2011.</strong></p>
<p>Information security breaches can compromise your business systems, and cause disruption to business operations. Being prepared and responding in a timely and effective way can mean the difference between minor incident and a business disaster. Using an information</p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 336x280, Ajdin */
google_ad_slot = "2018513310";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p>security incident management system enables organizations to have the controls and procedures in place to manage a wide variety of security incidents and vulnerabilities.</p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p><strong>ISO/IEC 27035:2011</strong>,<strong> Information technology – Security techniques – Information security incident management</strong>, gives “how to” guidance on detecting, reporting and assessing information security incidents and vulnerabilities.</p>
<p>It will help organizations respond to information security incidents, including the activation of appropriate controls for the prevention and reduction of, and recovery from, impacts, and, in so doing, learn and improve their overall approach.</p>
<p>Integrating an information security incident management system offers several benefits:</p>
<p>Read more text<a href="http://www.iso.org"> http://www.iso.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/1601/isoiec-270352011-information-technology-%e2%80%93-security-techniques-%e2%80%93-information-security-incident-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Utility Investment in Cyber Security for Industrial Control Systems to Total $4.1 Billion by 2018, Forecasts Pike Research</title>
		<link>http://quality-news.com/1080/utility-investment-in-cyber-security-for-industrial-control-systems-to-total-4-1-billion-by-2018-forecasts-pike-research/</link>
		<comments>http://quality-news.com/1080/utility-investment-in-cyber-security-for-industrial-control-systems-to-total-4-1-billion-by-2018-forecasts-pike-research/#comments</comments>
		<pubDate>Tue, 23 Aug 2011 09:06:26 +0000</pubDate>
		<dc:creator>QualityEditor</dc:creator>
				<category><![CDATA[Quality control]]></category>
		<category><![CDATA[Quality management]]></category>
		<category><![CDATA[Quality tools]]></category>
		<category><![CDATA[Basic Quality]]></category>
		<category><![CDATA[Basic Quality tools]]></category>
		<category><![CDATA[Quality]]></category>
		<category><![CDATA[Quality Assurance]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=1080</guid>
		<description><![CDATA[BOULDER, Colo.&#8211;(BUSINESS WIRE)&#8211;At one time in the not-too-distant past, electrical grids were controlled by electromechanical and pneumatic devices. Now, they are controlled by computers running Windows or Linux, using the Internet Protocol (IP) to communicate. Wireless and Bluetooth capabilities are appearing in supervisory control and data acquisition (SCADA) devices that are integral to the backbone [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://quality-news.com/wp-content/uploads/2011/08/Cyber-Security.jpg"><img class="alignleft size-thumbnail wp-image-1081" src="http://quality-news.com/wp-content/uploads/2011/08/Cyber-Security-150x150.jpg" alt="" width="150" height="150" /></a><strong>BOULDER, Colo</strong>.&#8211;(BUSINESS WIRE)&#8211;At one time in the not-too-distant past, electrical grids were controlled by electromechanical and pneumatic devices. Now, they are controlled by computers running <strong>Windows or Linux</strong>, using the Internet Protocol (IP) to communicate. Wireless and Bluetooth capabilities are appearing in supervisory control and data acquisition (SCADA) devices that are integral to the backbone of grid operations. All of these new features open an entire world of possibilities for more efficient utility operations, but also an entire world of risks. According to a new report published by Pike Research, such risks to the electrical grid will require utilities to make significant new investments in cyber security for industrial control systems (ICS), which the cleantech market intelligence firm forecasts will total<strong> $4.1 billion</strong> during</p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 336x280, Ajdin */
google_ad_slot = "2018513310";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p>the years between 2011 and 2018.</p>
<p>“The smart grid changes everything, but when it comes to cyber security issues, much of the story remains the same,” says senior analyst Bob Lockhart. “Integrating information technology into a power grid presents enormous potential to deliver energy more efficiently and profitably, but also brings inherent risks in terms of security vulnerabilities. The discovery of the Stuxnet worm in 2010 shone a bright light on the fragility of industrial control systems such as<strong> SCADA</strong>, and has created a new urgency among security vendors and utility managers alike. Nearly overnight,<strong> ICS security</strong> went from being a non-issue to being critical.”</p>
<p>Lockhart adds that ICS security initiatives will include major investments in control consoles and systems, telecommunications security, human-machine interfaces, and sensors and collectors. The ICS security enhancements will serve key grid operations application areas such as distribution automation, substation automation, and transmission upgrades. Pike Research’s analysis further indicates that smart grid deployments are not globally uniform, and thus some technology upgrades have been addressed earlier than others. For example, utilities tend to mitigate risks in transmission grids first, because a single outage in transmission can have such a wide-ranging effect.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
The firm forecasts that<strong> ICS security</strong> investments will increase at a relatively steady rate over the next seven years, rising from $309 million in 2011 to<strong> $692 million</strong> annually by 2018. In addition to this revenue, a significant number of professional services opportunities exist, including development and maintenance of security reference architectures for utilities’ control networks, development of security policies and procedures, maintaining employee security awareness programs for ICS, and change management, among others.</p>
<p>&nbsp;</p>
<p>Read more text <a href="http://www.businesswire.com">http://www.businesswire.com</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/1080/utility-investment-in-cyber-security-for-industrial-control-systems-to-total-4-1-billion-by-2018-forecasts-pike-research/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are information security risks threatening your business? New and improved ISO/IEC 27005 standard beefs up protection</title>
		<link>http://quality-news.com/983/are-information-security-risks-threatening-your-business-new-and-improved-isoiec-27005-standard-beefs-up-protection/</link>
		<comments>http://quality-news.com/983/are-information-security-risks-threatening-your-business-new-and-improved-isoiec-27005-standard-beefs-up-protection/#comments</comments>
		<pubDate>Wed, 03 Aug 2011 09:16:05 +0000</pubDate>
		<dc:creator>QualityEditor</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[ISO Standards]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[ISO STANDARD]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=983</guid>
		<description><![CDATA[The International Standard ISO/IEC 27005:2011 which gives managers and staff in IT departments a framework for implementing a risk management approach to assist them in managing their information security management system (ISMS) risks.  ©ISO, Alexane Rosa Information security risks pose a considerable threat to businesses due to the possibility of financial loss or damage, loss [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://quality-news.com/wp-content/uploads/2011/08/ISO_IEC_27005_NISO27k_banner.jpg"><img class="alignleft size-thumbnail wp-image-984" src="http://quality-news.com/wp-content/uploads/2011/08/ISO_IEC_27005_NISO27k_banner-150x150.jpg" alt="" width="150" height="150" /></a>The International <strong>Standard ISO/IEC 27005:2011</strong> which gives managers and staff in IT departments a framework for implementing a risk management approach to assist them in managing their information security management system (ISMS) risks.</p>
<div>
<p><strong> ©ISO, Alexane Rosa</strong></p>
<div>Information security risks pose a considerable threat to businesses due to the possibility of financial loss or damage, loss of essential network services, or loss of reputation and customer confidence. Risk management is one of the key elements in preventing online fraud, identity theft, damage to Web sites, loss of personal data and many other information security incidents. Without a solid risk management framework,</div>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 336x280, Ajdin */
google_ad_slot = "2018513310";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<div>organizations expose themselves to many types of cyber threats.</div>
</div>
<p>The new International Standard <strong>ISO/IEC 27005:2011, </strong><strong><em>Information technology – Security techniques – Information security risk management</em></strong>, will help organizations of all types to better manage their information security risks.</p>
<p>It describes the information security risk management process and associated actions, and supports the general concepts specified in ISO/IEC 27001:2005,<em> Information technology – Security techniques – Information security management systems – Requirements.</em></p>
<p>Edward Humphreys, Convener of the ISO/IEC working group that developed the standard comments:</p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
<strong>“ISO/IEC 27005:2011</strong> is an essential standard for those that want to manage their risks effectively and, in particular, to comply with the popular information security management system standard ISO/IEC 27001. Risk management is critical to good business governance, and this standard helps organizations with advice on the why, what and how of managing information security risks in support of their governance objectives.”</p>
<p>In this second edition, the framework outlined in ISO/IEC 27005 has been reviewed and updated to reflect the content of the risk management documents:</p>
<p>&nbsp;</p>
<p>Read more text<a href="http://www.iso.org"> http://www.iso.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/983/are-information-security-risks-threatening-your-business-new-and-improved-isoiec-27005-standard-beefs-up-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are You a Data Breach Victim? Here&#8217;s What to Do</title>
		<link>http://quality-news.com/796/are-you-a-data-breach-victim-heres-what-to-do/</link>
		<comments>http://quality-news.com/796/are-you-a-data-breach-victim-heres-what-to-do/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 07:39:43 +0000</pubDate>
		<dc:creator>QualityEditor</dc:creator>
				<category><![CDATA[Human Resources]]></category>
		<category><![CDATA[Quality management]]></category>
		<category><![CDATA[Quality tools]]></category>
		<category><![CDATA[Human Error]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Quality control]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=796</guid>
		<description><![CDATA[Alas, another day, another data breach. Late Thursday, word broke that the hacker group LulzSec broke into SonyPictures.com and gained access to 1 million user accounts (the group apparently posted details for 50,000 accounts online). If you have a Sony Pictures account, the bad news is that your personal information may be out there. You [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://quality-news.com/wp-content/uploads/2011/06/data-breach.jpg"><img class="alignleft size-thumbnail wp-image-797" src="http://quality-news.com/wp-content/uploads/2011/06/data-breach-150x150.jpg" alt="Are You a Data Breach Victim? Here's What to Do" width="150" height="150" /></a>Alas, another day, another data breach. Late Thursday, word broke that the hacker group<strong> LulzSec broke into SonyPictures.com</strong> and gained access to 1 million user accounts (the group apparently posted details for 50,000 accounts online). If you have a Sony Pictures account, the bad news is that your personal information may be out there. You can&#8217;t change that fact, but you can take a few steps to limit the potential for damage.</p>
<p>PC World — 															Alas, another day, another data breach. Late Thursday,  word broke that the hacker group LulzSec broke into SonyPictures.com and  gained access to 1 million user accounts (the group apparently posted details for 50,000 accounts online). If  you have a Sony Pictures account, the bad news is that your personal  information may be out there.</p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 336x280, Ajdin */
google_ad_slot = "2018513310";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p>You can&#8217;t change that fact, but you can  take a few steps to limit the potential for damage.</p>
<p>&nbsp;</p>
<p><strong>1. Change Your Passwords.</strong></p>
<p>This should be the first thing you  do: Change your password for your account on the impacted site. If you  used the same login information for any other sites, you should change  your password on those sites too. And this may be a good time to change  your approach to passwords&#8211;check out <strong>Alex Wawro&#8217;s</strong> story on how to build better passwords without losing your mind.</p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p>&nbsp;</p>
<p><strong>2. Watch for Phishing Attempts, Malicious E-mail</strong></p>
<p>If your  e-mail address gets exposed in a data breach, scammers, spammers, and  malware authors may try to send malicious e-mails to you&#8211;well, more  than usual, anyway&#8211;so you may see a spike in spam. As always, be on the  lookout for any suspicious-looking e-mail<strong>. Don&#8217;t open attachments</strong> you  weren&#8217;t expecting&#8211;even from people you know. Don&#8217;t click links in  e-mail messages.</p>
<p>&nbsp;</p>
<p>read at <a href="http://www.cio.com">http://www.cio.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/796/are-you-a-data-breach-victim-heres-what-to-do/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO standard makes sure that PINs are secure</title>
		<link>http://quality-news.com/622/iso-standard-makes-sure-that-pins-are-secure/</link>
		<comments>http://quality-news.com/622/iso-standard-makes-sure-that-pins-are-secure/#comments</comments>
		<pubDate>Sun, 08 May 2011 07:53:38 +0000</pubDate>
		<dc:creator>QualityEditor</dc:creator>
				<category><![CDATA[ISO 9001]]></category>
		<category><![CDATA[ISO Standards]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[ISO 9001:2008]]></category>
		<category><![CDATA[ISO STANDARD]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=622</guid>
		<description><![CDATA[How many times and in how many places have you entered your bank card’s PIN (Personal Identification Number) today? To make sure that the integrity of this data is protected throughout all transactions, ISO has technically revised and updated the standard providing requirements for the management and security of PINs (ISO 9564-1). Why an International [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://quality-news.com/wp-content/uploads/2011/05/iso1.png"><img class="alignleft size-medium wp-image-625" src="http://quality-news.com/wp-content/uploads/2011/05/iso1-277x300.png" alt="ISO standard to secure your pin" width="103" height="112" /></a>How many times and in how many places have you entered your bank card’s  PIN (<strong>Personal Identification Number</strong>) today? To make sure that the  integrity of this<strong> data is protected throughout all transactions</strong>, ISO has  technically revised and updated the standard providing requirements for  the management and security of <strong>PINs (ISO 9564-1</strong>).</p>
<p>Why an International Standard for PIN management? Take the example of  just one financial institution, Visa. In 2007, Visa had 20 000 member  banks with 1.59 billion cards in circulation generating 59 billion  transactions per year, with peaks of more than 6 800 transactions per  second. <strong></strong></p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 336x280, Ajdin */
google_ad_slot = "2018513310";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p><strong>The ISO standard for PIN</strong> management helps protect the  identification numbers used for cardholder verification against  unauthorized disclosure, compromise and misuse everywhere in the world.  It thus helps minimize the risk of fraud through electronic funds  transfer systems.</p>
<p><br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<p><strong>Mark Sutton</strong>, Chair of the ISO subcommittee that developed the  standard,explains, “A PIN’s life span may be long and involve its use in  many different countries, bank machines, shops, and even online. Its  secrecy needs to be assured at all times, both for online and offline  transactions, from the moment it is established to its deactivation  (including any<span style="text-decoration: underline;"> issuances, storage, entries, transmissions, validations</span>,  etc.).”</p>
<p><strong>ISO 9564-1:2011, </strong><strong><em>Financial services – Personal Identification Number (PIN) management and security</em></strong><strong> – Part 1: </strong><strong><em>Basic principles and requirements for PINs in card-based systems, </em></strong>specifies  principles and techniques that provide the minimum security measures  required for effective international PIN management. These measures are  applicable to institutions responsible for the management and protection  of PINs during their creation, issuance, usage and deactivation.<br />
Online and offline PIN verification may have very different security  requirements. Since online PINs can be verified independent of the card  itself, any type of payment card or device can be used to initiate a  transaction. However, there are special requirements for cards used in  offline verifications. In particular because the latter type does not  require that a cardholder’s PIN be sent to the issuer host for  verification.<br />
read at <a href="http://www.iso.org">http://www.iso.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/622/iso-standard-makes-sure-that-pins-are-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why ISO 27001 is not enough</title>
		<link>http://quality-news.com/394/why-iso-27001-is-not-enough/</link>
		<comments>http://quality-news.com/394/why-iso-27001-is-not-enough/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 13:28:55 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[iso 27001]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=394</guid>
		<description><![CDATA[Since its publication in October 2005, ISO 27001 has been implemented in many organisations as the best practice for information security management, with over three hundred UK organisations independently certified against the standard. So if these organisations, which range from small and medium to large enterprises, have implemented ISO 27001, why are we still hearing [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_158" class="wp-caption alignleft" style="width: 144px"><img class="size-full wp-image-158" title="Infromation security" src="http://quality-news.com/wp-content/uploads/2009/06/security300x350.jpg" alt="Infromation security" width="134" height="156" /><p class="wp-caption-text">Infromation security</p></div>
<p>Since its publication in October 2005, ISO 27001 has been implemented in many organisations as the best practice for information security management, with over three hundred UK organisations independently certified against the standard.</p>
<p>So if these organisations, which range from small and medium to large enterprises, have implemented ISO 27001, why are we still hearing about lapses in information security? Neil O&#8217;Connor, principal consultant, Activity asks what lessons are there to be learnt from every organisation, whatever its size, using ISO 27001 as a benchmark?</p>
<p>Introduction</p>
<p>Information security, and in particular the handling of personal information, has regularly been in the headlines over the last few months. There have been notable incidents at HM Revenue and Customs, the Ministry of Defence, Nationwide Building Society and Marks and Spencer among others.<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br></p>
<p>These are all large organisations implementing information security management systems at least compliant with, if not certified against, the international standard for information security management, ISO 27001.</p>
<p>ISO27001<br />
<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br><br />
A key issue is that ISO 27001 is a management standard, not a security standard. It provides a framework for the management of security within an organisation, but does not provide a &#8216;Gold Standard&#8217; for security, which, if implemented, will ensure the security of an organisation.</p>
<p>ISO 27001 takes a risk assessment based approach. An information security risk assessment is used to identify the security requirements of the organisation, and to then identify the security controls needed to bring that risk within an acceptable level for the organisation.</p>
<p>Once the security controls have been identified, ISO 27001 defines processes to ensure that a) these controls are implemented and are effective; and b) that the controls continue to meet the organisation&#8217;s security needs.</p>
<p>read full text <a href="http://www.bcs.org/server.php?show=ConWebDoc.26594">on bcs.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/394/why-iso-27001-is-not-enough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO standard to ensure structures are not &#8220;gone with the wind&#8221;</title>
		<link>http://quality-news.com/302/iso-standard-to-ensure-structures-are-not-gone-with-the-wind/</link>
		<comments>http://quality-news.com/302/iso-standard-to-ensure-structures-are-not-gone-with-the-wind/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 07:11:47 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO Standards]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[structures]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=302</guid>
		<description><![CDATA[ISO.ORG gives us ISO 4354, Wind actions on structures was prepared by the ISO technical committee ISO/TC 98, Bases for design of structures, subcommittee SC 3, Loads, forces and other actions. A new International Standard, ISO 4354, Wind actions on structures, will help ensure the reliability of structures in areas exposed to strong winds and [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-303" title="wind-farm" src="http://quality-news.com/wp-content/uploads/2009/06/wind-farm.jpg" alt="wind-farm" width="400" height="300" /><br />
ISO.ORG gives us<br />
<code>ISO 4354, Wind actions on structures was prepared by the ISO technical committee ISO/TC 98, Bases for design of structures, subcommittee SC 3, Loads, forces and other actions. </code><br />
A new International Standard, ISO 4354, Wind actions on structures, will help ensure the reliability of structures in areas exposed to strong winds and cyclones.<br />
The standard describes the actions of wind on structures, and specifies methods for calculating characteristic values of wind loads.<br />
“Perhaps one of the biggest advantages of ISO 4354 is that it allows you to bridge the gaps of all wind loading codes around the world,” says Prof. William Melbourne, Convenor of the working group that developed the standard.<br />
<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br><br />
“The standard provides methodology for calculating wind loads on structures, some of which have never been available in this form before. It cancels and replaces the first edition of the standard, originally published in 1997, with a full technical revision” concludes Prof. Melbourne.  The standard covers design methodologies for three main storm types: synoptic winds (large scale winds), thunderstorms and topical cyclones (hurricanes, typhoons).<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
It provides the basic methods for determining wind loading analytically for simple structures and guidance for the design of more complex structures.  ISO 4354 will be useful for structural engineers involved in the design of buildings, towers, chimneys, bridges and other structures, and their components and appendages. The standard will be of particular interest for countries without an adequate wind loading standard.</p>
<p>red full text on <a href="http://www.iso.org/iso/pressrelease.htm?refid=Ref1232">iso.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/302/iso-standard-to-ensure-structures-are-not-gone-with-the-wind/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>overview of information security management systems</title>
		<link>http://quality-news.com/157/overview-of-information-security-management-systems/</link>
		<comments>http://quality-news.com/157/overview-of-information-security-management-systems/#comments</comments>
		<pubDate>Sun, 07 Jun 2009 19:35:54 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[17799]]></category>
		<category><![CDATA[ISO STANDARD]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=157</guid>
		<description><![CDATA[With more and more organizations implementing information security management systems (ISMS) as part of their risk management strategy, the publication of a new ISO/IEC standard giving an overview of ISMS is particularly timely. Information securityISO/IEC 27000:2009, Information technology – Security techniques – Information security management systems – Overview and vocabulary, will assist organizations of all [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_158" class="wp-caption aligncenter" style="width: 310px"><img class="size-full wp-image-158" title="Infromation security" src="http://quality-news.com/wp-content/uploads/2009/06/security300x350.jpg" alt="Infromation security" width="300" height="350" /><p class="wp-caption-text">Infromation security</p></div>
<p>With more and more organizations implementing information security management systems (ISMS) as part of their risk management strategy, the publication of a new ISO/IEC standard giving an overview of ISMS is particularly timely.</p>
<p>Information securityISO/IEC 27000:2009, Information technology – Security techniques – Information security management systems – Overview and vocabulary, will assist organizations of all types to understand the fundamentals, principles and concepts to improve protection of their information assets.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
Applicable to all types and sizes of organization (e.g. commercial enterprises, government agencies, non-profit organizations), ISO/IEC 27000:2009 supplements the ISO/IEC 27000 family of standards by providing an introduction to information security management and defining related terms.</p>
<p>Today, an organization&#8217;s information assets are dependent upon information and communications technology. The technology assists in facilitating the creation, processing, storing, transmitting, protection and destruction of information.</p>
<p>As the extent of the interconnected global business environment expands, so does the requirement to protect information as it is exposed to a wider variety of threats and vulnerabilities.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
Edward Humphreys, convenor of the working group, which developed the standard, comments: &#8220;Standardized security techniques are becoming mandatory requirements for e-commerce, health-care, telecoms, automotive and many other application areas in both the commercial and government sectors. ISO/IEC 27000:2009, together with the other ISO/IEC 27000 family of standards, aims to assist organizations more effectively achieve an appropriate level of information security.&#8221;</p>
<p>red full story <a href="http://www.iso.org/iso/pressrelease.htm?refid=Ref1223">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/157/overview-of-information-security-management-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced

Served from: quality-news.com @ 2012-05-21 18:31:10 -->
