<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Quality News &#187; security</title>
	<atom:link href="http://quality-news.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://quality-news.com</link>
	<description>News about ISO standards and Quality Management</description>
	<lastBuildDate>Mon, 01 Feb 2010 15:36:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Why ISO 27001 is not enough</title>
		<link>http://quality-news.com/394/why-iso-27001-is-not-enough/</link>
		<comments>http://quality-news.com/394/why-iso-27001-is-not-enough/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 13:28:55 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[iso 27001]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=394</guid>
		<description><![CDATA[Since its publication in October 2005, ISO 27001 has been implemented in many organisations as the best practice for information security management, with over three hundred UK organisations independently certified against the standard.
So if these organisations, which range from small and medium to large enterprises, have implemented ISO 27001, why are we still hearing about [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_158" class="wp-caption alignleft" style="width: 144px"><img class="size-full wp-image-158" title="Infromation security" src="http://quality-news.com/wp-content/uploads/2009/06/security300x350.jpg" alt="Infromation security" width="134" height="156" /><p class="wp-caption-text">Infromation security</p></div>
<p>Since its publication in October 2005, ISO 27001 has been implemented in many organisations as the best practice for information security management, with over three hundred UK organisations independently certified against the standard.</p>
<p>So if these organisations, which range from small and medium to large enterprises, have implemented ISO 27001, why are we still hearing about lapses in information security? Neil O&#8217;Connor, principal consultant, Activity asks what lessons are there to be learnt from every organisation, whatever its size, using ISO 27001 as a benchmark?</p>
<p>Introduction</p>
<p>Information security, and in particular the handling of personal information, has regularly been in the headlines over the last few months. There have been notable incidents at HM Revenue and Customs, the Ministry of Defence, Nationwide Building Society and Marks and Spencer among others.<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br></p>
<p>These are all large organisations implementing information security management systems at least compliant with, if not certified against, the international standard for information security management, ISO 27001.</p>
<p>ISO27001<br />
<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br><br />
A key issue is that ISO 27001 is a management standard, not a security standard. It provides a framework for the management of security within an organisation, but does not provide a &#8216;Gold Standard&#8217; for security, which, if implemented, will ensure the security of an organisation.</p>
<p>ISO 27001 takes a risk assessment based approach. An information security risk assessment is used to identify the security requirements of the organisation, and to then identify the security controls needed to bring that risk within an acceptable level for the organisation.</p>
<p>Once the security controls have been identified, ISO 27001 defines processes to ensure that a) these controls are implemented and are effective; and b) that the controls continue to meet the organisation&#8217;s security needs.</p>
<p>read full text <a href="http://www.bcs.org/server.php?show=ConWebDoc.26594">on bcs.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/394/why-iso-27001-is-not-enough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO standard to ensure structures are not &#8220;gone with the wind&#8221;</title>
		<link>http://quality-news.com/302/iso-standard-to-ensure-structures-are-not-gone-with-the-wind/</link>
		<comments>http://quality-news.com/302/iso-standard-to-ensure-structures-are-not-gone-with-the-wind/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 07:11:47 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO Standards]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[structures]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=302</guid>
		<description><![CDATA[
ISO.ORG gives us
ISO 4354, Wind actions on structures was prepared by the ISO technical committee ISO/TC 98, Bases for design of structures, subcommittee SC 3, Loads, forces and other actions. 
A new International Standard, ISO 4354, Wind actions on structures, will help ensure the reliability of structures in areas exposed to strong winds and cyclones.
The [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-303" title="wind-farm" src="http://quality-news.com/wp-content/uploads/2009/06/wind-farm.jpg" alt="wind-farm" width="400" height="300" /><br />
ISO.ORG gives us<br />
<code>ISO 4354, Wind actions on structures was prepared by the ISO technical committee ISO/TC 98, Bases for design of structures, subcommittee SC 3, Loads, forces and other actions. </code><br />
A new International Standard, ISO 4354, Wind actions on structures, will help ensure the reliability of structures in areas exposed to strong winds and cyclones.<br />
The standard describes the actions of wind on structures, and specifies methods for calculating characteristic values of wind loads.<br />
“Perhaps one of the biggest advantages of ISO 4354 is that it allows you to bridge the gaps of all wind loading codes around the world,” says Prof. William Melbourne, Convenor of the working group that developed the standard.<br />
<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br><br />
“The standard provides methodology for calculating wind loads on structures, some of which have never been available in this form before. It cancels and replaces the first edition of the standard, originally published in 1997, with a full technical revision” concludes Prof. Melbourne.  The standard covers design methodologies for three main storm types: synoptic winds (large scale winds), thunderstorms and topical cyclones (hurricanes, typhoons).<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
It provides the basic methods for determining wind loading analytically for simple structures and guidance for the design of more complex structures.  ISO 4354 will be useful for structural engineers involved in the design of buildings, towers, chimneys, bridges and other structures, and their components and appendages. The standard will be of particular interest for countries without an adequate wind loading standard.</p>
<p>red full text on <a href="http://www.iso.org/iso/pressrelease.htm?refid=Ref1232">iso.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/302/iso-standard-to-ensure-structures-are-not-gone-with-the-wind/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>overview of information security management systems</title>
		<link>http://quality-news.com/157/overview-of-information-security-management-systems/</link>
		<comments>http://quality-news.com/157/overview-of-information-security-management-systems/#comments</comments>
		<pubDate>Sun, 07 Jun 2009 19:35:54 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[17799]]></category>
		<category><![CDATA[ISO STANDARD]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=157</guid>
		<description><![CDATA[With more and more organizations implementing information security management systems (ISMS) as part of their risk management strategy, the publication of a new ISO/IEC standard giving an overview of ISMS is particularly timely.
Information securityISO/IEC 27000:2009, Information technology – Security techniques – Information security management systems – Overview and vocabulary, will assist organizations of all types [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_158" class="wp-caption aligncenter" style="width: 310px"><img class="size-full wp-image-158" title="Infromation security" src="http://quality-news.com/wp-content/uploads/2009/06/security300x350.jpg" alt="Infromation security" width="300" height="350" /><p class="wp-caption-text">Infromation security</p></div>
<p>With more and more organizations implementing information security management systems (ISMS) as part of their risk management strategy, the publication of a new ISO/IEC standard giving an overview of ISMS is particularly timely.</p>
<p>Information securityISO/IEC 27000:2009, Information technology – Security techniques – Information security management systems – Overview and vocabulary, will assist organizations of all types to understand the fundamentals, principles and concepts to improve protection of their information assets.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
Applicable to all types and sizes of organization (e.g. commercial enterprises, government agencies, non-profit organizations), ISO/IEC 27000:2009 supplements the ISO/IEC 27000 family of standards by providing an introduction to information security management and defining related terms.</p>
<p>Today, an organization&#8217;s information assets are dependent upon information and communications technology. The technology assists in facilitating the creation, processing, storing, transmitting, protection and destruction of information.</p>
<p>As the extent of the interconnected global business environment expands, so does the requirement to protect information as it is exposed to a wider variety of threats and vulnerabilities.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
Edward Humphreys, convenor of the working group, which developed the standard, comments: &#8220;Standardized security techniques are becoming mandatory requirements for e-commerce, health-care, telecoms, automotive and many other application areas in both the commercial and government sectors. ISO/IEC 27000:2009, together with the other ISO/IEC 27000 family of standards, aims to assist organizations more effectively achieve an appropriate level of information security.&#8221;</p>
<p>red full story <a href="http://www.iso.org/iso/pressrelease.htm?refid=Ref1223">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/157/overview-of-information-security-management-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
