CERT

Governing for Enterprise Security Implementation Guide

Added by the EDUCAUSE Librarian
Title:Governing for Enterprise Security Implementation Guide (ID: CSD5564)
Source:CERT
Origin:Contributed by Organizations or Campuses (08/24/2007)
Type:Articles, Papers, and Reports
Abstract:

This guide is designed to help business leaders implement an effective program to govern information technology (IT) and information security. Our objective is to help you make well-informed decisions about many important components of governing for enterprise security (GES), such as adjusting organizational structure, designating roles and responsibilities, allocating resources (including security investments), managing risks, measuring results, and gauging the adequacy of security audits and reviews. The intent in elevating security to a governance-level concern is to foster attentive, security-conscious leaders who are better positioned to protect an organization's digital assets, its operations, its market position, and its reputation.

View this resource:

Governing for Enterprise Security

Added by the EDUCAUSE Librarian
Title:Governing for Enterprise Security (ID: CSD5563)
Source:CERT
Origin:Contributed by Organizations or Campuses (11/18/2008)
Type:Web Sites
Abstract:

CERT's web site for Governing for Enterprise Security.

View this resource:

Incident Management Capability Metrics

Added by the EDUCAUSE Librarian
Title:Incident Management Capability Metrics (ID: CSD5144)
Source:CERT
Abstract:

The CERT CSIRT Development Team has introduced a method to evaluate and improve an organization's capability for managing computer security incidents. This method uses a set of incident management best practices defined in a set of metrics called the Incident Management Capability Metrics. These metrics provide organizations a baseline against which they can benchmark their current incident management processes or services.

The metrics questions explore different aspects of incident management activities. These questions are grouped into four basic functional categories:

  • Protect
  • Detect
  • Respond
  • Sustain

The results from an evaluation using the metrics will help an organization determine the maturity of its incident management capability regardless of organization type or sector (commercial, academic, government, etc.).

View this resource: