Posts

Killing the Cyber Security Kill Chain

Image
image :oreilly Threat Modelling aims to identify threats and vulnerabilities to apply controls to mitigate the risks. Killing the Cyber Security Kill Chain is an approach for Threat Modelling with ISO 27001 controls.      KILLING THE CYBER SECURITY KILL CHAIN from Niranjan Meegammana Niranjan Meegammana

Why you need information security policy?

Image
Image : Bizsecure Your web site is hacked!  Your customer data is stolen!   What would you do? Isn't it a good idea to refer to your Information Security Policy first? A policy define values and views of the organization. They are the fundamental  rules and regulations that governs the organization. All employees must follow the policies to run the business smoothly. They enforce a centralized control over it's business activities and resources. Some organization policies provide guidance to  employees, and others help protect the business from legal risks.  Policies are general statements, which state how an organization should act. Procedures define exactly how a task to be  performed step by step. Guidelines are further advise to execute a procedure. An information security policy is aims to protect information assets of an organization. They are set of instructions to employees to prevent data breaches. A security policy is important to identify ri...

Why risk based approach is a better defence?

Image
What is the best approach to address your organisation's information security issues? There are common as well as your business specific Information security threats and mitigation techniques to handle them.  For instance, you may already may have  staff  training, anti-malware and other technologies in place. However, you may not know how effective is your defences until meet a real threat. This requires every organisation to build their defence according to the potential information security risks they might face. So, what actually is a risk-based defence? Your organization does not have an unlimited budget for information security. This requires you to best use available resources carefully to build your defence. The best approach is to conduct a risk assessment, identify risks and  prioritize your risks. Then you can implement appropriate controls to mitigate your risks. ISO 27001 ISMS standard provides you a framework to follow a  risk-based approach to mee...

Why your organization need ISO 27001?

Image
ISO 27001 is the most comprehensive international standard  ISMS (Information Security Management System).  1. ISO 270001 based ISMS provides you a systematic approach that consist  processes, technology and people to help you for  effective risk management to protect your organisatin's information.  2. In a world of rising cyber crime ISO 27001 gives your organisation an independent, expert verification of your information security practices.  3. It helps you comply with the EU GDPR (General Data Protection Regulation)   4. ISO 27001 ensures legal and regulatory compliance for data protection. 5. It gives you a competitive advantage with defence measures for information security. 6. With ISO 27001 certification an organization gains trust of customers, suppliers and investors that their information is protected. individual , you are more  7. ISO 27001 improves your  information security posture with controls that protect your data ...

Why you need an ISMS?

Image
An ISMS (Information Security Management System) is a framework which help you manage yor your organisation’s information security. It enables you to assess, manage, monitor, review and improve your information security practices.  With an ISMS you will develop policies, procedures, guidelines and controls to meet three objectives of information security:  1. Confidentiality:  You will ensure that your data can only be accessed by authorized people.  2  Integrity: You will keep your data accurate and complete, where they will only be modified in an authorized manner only. 3. Availability:  You will make sure that your data can be accessed when it’s required. Further more an ISMS : Help you protect various forms of data including  intellectual property, data on cloud, company secrets, data on devices and hard copies and personal information. Reduce your cyber attack surface and increase your attack resilience Reduce your information security costs with ...

Cyber Security Awareness Free!

Image
How secure is your business against a data breach threat?  Would you like to plan a Cyber Security strategy to manage the risks to your data?  Get a free Consultation today.  WhatsApp 0718188096 your name, organisation to learn more on this offer. Click this link to sign up to join upcoming free awareness session. https://forms.gle/2uNUkzbXL1jM3Bot8 Shilpa Sayura FoundationN NextGen Skills Now! Loading…

What is Business Continuity Management?

Image
image : EC council Business Continuity Management (BCM) can be simply explained as planning to survive from disruptive incidents. Disasters struck when you least expect it. The cause of the disaster could be a natural or a human factor. Whatever the disaster your organisation need to be prepared. What are the types of disasters impact your information systems ? Data Breaches Hacking of Systems  Critical application failure  Employee sabotage Service provider outage  Power outages Communication outages Internet outage Fire, Floods etc. Natural Disasters  Ask your self : What areas of business will each of above disaster impact? What will be the liklyhood of it happening? What will be your loss?  How would you recover? How long the recovery will take? What would it cost? Although you may not have perfect answers, you need them.  BCM is a process that will help you identify potential threats, and their impact on your business operations. In the event of a dis...