Security Certification
Information Security Governance: Standardizing the Practice of Information Security
| Title: | Information Security Governance: Standardizing the Practice of Information Security (ID: ERB0817) | | Author(s): | Tammy L. Clark (Georgia State University) and Toby D. Sitko (EDUCAUSE) | | Origin: | Documents Contributed by ECAR, Research Bulletins (08/19/2008) | | Type: | Articles, Papers, and Reports | | Abstract: | This ECAR research bulletin discusses the trend to use a variety of risk assessment frameworks and standards to create an information security program that is sufficiently comprehensive for colleges and universities. These standards include the Control Objectives for Information and related Technology (CobiT) IT control framework, the Information Technology Infrastructure Library (ITIL) service management framework, and the set of information control objectives now commonly referred to as ISO 27001. In specific, the process of implementing this framework at Georgia State University (GSU) is discussed. In addition, the bulletin provides a rationale for an information security governance framework that enables executives to see the degree to which their information security programs are effective in assessing and mitigating risks, protecting confidential data, aligning goals with institutional academic and business objectives, and continuously improving over time. | | View this resource: | This publication is currently password protected. All faculty, staff, and students from institutions that have subscribed to ECAR at the ECAR Participating, Comprehensive Content, Corporate, and Research Bulletins Package levels are authorized to access this publication by using their EDUCAUSE personal profile. |
IT Security Essential Body of Knowledge: A Competency and Functional Framework for IT Security Workforce Development
| Title: | IT Security Essential Body of Knowledge: A Competency and Functional Framework for IT Security Workforce Development (ID: LIVE0722) | | Author(s): | Brenda Oldfield (United States Department of Homeland Security) | | Origin: | EDUCAUSE Live!, Web Seminars Contributed by EDUCAUSE (11/14/2007) | | Type: | Presentations/Speeches | | Abstract: | The Department of Homeland Security's National Cyber Security Division worked with subject matter experts from government, the private sector, and academia to develop an umbrella framework that establishes a national baseline representing the essential knowledge and skills IT security practitioners must have to perform their jobs. The IT Security EBK builds directly on established work and is not intended to represent a standard, directive, or policy by DHS. Instead, it further clarifies key IT security terms and concepts for well-defined competencies, identifies notional security roles, and defines primary functional perspectives to help advance the IT security training and certification landscape as we strive to ensure that we have the most qualified and appropriately trained IT security workforce possible. | | View this resource: | |
Tune In Nov. 14: Free Web Seminar on IT Security Essential Body of Knowledge for Workforce Development
The Department of Homeland Security's National Cyber Security Division worked with subject matter experts from government, the private sector, and academia to develop an umbrella framework that establishes a national baseline representing the essential knowledge and skills IT security practitioners must have to perform their jobs. The IT Security EBK builds directly on established work and is not intended to represent a standard, directive, or policy by DHS. Instead, it further clarifies key IT security terms and concepts for well-defined competencies, identifies notional security roles, and defines primary functional perspectives to help advance the IT security training and certification landscape as we strive to ensure that we have the most qualified and appropriately trained IT security workforce possible.
Tune In Nov. 14: Free Web Seminar on IT Security Essential Body of Knowledge for Workforce Development
The Department of Homeland Security's National Cyber Security Division worked with subject matter experts from government, the private sector, and academia to develop an umbrella framework that establishes a national baseline representing the essential knowledge and skills IT security practitioners must have to perform their jobs. The IT Security EBK builds directly on established work and is not intended to represent a standard, directive, or policy by DHS. Instead, it further clarifies key IT security terms and concepts for well-defined competencies, identifies notional security roles, and defines primary functional perspectives to help advance the IT security training and certification landscape as we strive to ensure that we have the most qualified and appropriately trained IT security workforce possible.
Information Technology (IT) Security Essential Body of Knowledge (EBK): A Competency and Functional Framework for IT Security Workforce Development
| Title: | Information Technology (IT) Security Essential Body of Knowledge (EBK): A Competency and Functional Framework for IT Security Workforce Development (ID: CSD5182) | | Origin: | Contributed by Organizations or Campuses (10/03/2007) | | Type: | Government Documents, Laws, Testimonies or Reports | | Abstract: | This federal register notice informs the public and interested stakeholders that the Department of Homeland Security (DHS) is making available for public review and comment ``Information Technology (IT) Security Essential Body of Knowledge (EBK): A Competency and Functional Framework for IT Security Workforce Development.'' This framework is intended to assist the public, private, and academic sectors with strategic IT security workforce development initiatives including professional development, training and education. The EBK is not an additional set of DHS guidelines, and it is not intended to represent a standard, directive, or policy by DHS. Instead, it further clarifies key IT security terms and concepts for well-defined competencies, identifies notional security roles, defines four primary functional perspectives, and establishes an IT Security Role, Competency, and Functional Matrix. | | View this resource: | |
IT Security Essential Body of Knowledge: Federal Register Notice Request for Comments
A Federal Register Notice has been published for the Department of Homeland Security's "Information Technology (IT) Security Essential Body of Knowledge (EBK): A Competency and Functional Framework for IT Security Workforce Development." The deadline for comments is December 7, 2007. According to the Notice: The EBK is not an additional set of DHS guidelines, and it is not intended to represent a standard, directive, or policy by DHS. Instead, it further clarifies key IT security terms and concepts for well-defined competencies, identifies notional security roles, defines four primary functional perspectives, and establishes an IT Security Role, Competency, and Functional Matrix. More information, including a downloadable version of the IT Security EBK, is available at http://www.us-cert.gov/ITSecurityEBK/
|