Archive for the 'implementation' Category

What is the difference between Regulations, Legislation, and Guidance

Different types of documentation serve different purposes. As the following list explains, some documentation is internally driven and some is externally driven. To prepare for the interview process for an information security position, you need to understand what types of internal security documentation the organization may have and what external security-related regulations the organization must […]

Popularity: 34% [?]

The Value of Accurate Financial Statements

Financial statements present information about an organization’s financial resources and liabilities at a point in time, the results of its activities during a particular period, and its flow of cash during that period. In the for-profit world, these statements focus on information that is useful in making investment and lending decisions. In the nonprofit world, […]

Popularity: 60% [?]

SOX and what would this mean for nonprofits?

What would this mean for nonprofits? This recommendation would require nonprofits to submit documentation every five years that proves to the IRS that the organization continues to comply with its 501(c )(3) designation. The list of documents specified here are particularly enlightening about the intent of this proposal:
• Current articles of incorporation and by-laws. The […]

Popularity: 42% [?]

How to create a well-written policy statements

The cornerstones of effective information security programs are well-written policy statements. This is the wellspring of all other directives, standards, procedures, guidelines, and other supporting documents. As with any assessment process, it is important to ensure that policies establish the direction management wants to go with regard to security
When reviewing policies, Thomas R. Peltier in […]

Popularity: 67% [?]

Security issues in online mortgage and loan applications

According to the Mortgage Bankers Association, online mortgage originations are expected to grow to $250 billion by 2003 from $4 billion in 1999 (although more recent estimates put that number much lower due to the economic turmoil in the technology sectors).
A number of companies have developed solutions suitable for this space, validating the need for […]

Popularity: 74% [?]

The Impact of Sarbanes-Oxley (SOX) Act on Information Security Governance

What do you think about the impact of SOX implementation for infosec governance? Gurpreet Dhillon and Sushma Mishra from Virginia Commonwealth University, USA said that SOX has created challenges and set new standards for IT governance in companies. To fully comply with the law, companies will need to improve information quality to insure transparency and […]

Popularity: 100% [?]

Four approach to IT risk for successful Sarbanes Oxley implementation

There are a lot of definitions of IT risk, below is the definition of IT risk from Sarbanes Oxley perspective. But, before let you know that every business venture is basically risky. In new business ventures and new product development, there are unknown factors and their impacts on the venture are equally unknown. The unknown […]

Popularity: 46% [?]