Mostrando entradas con la etiqueta Documentation. Mostrar todas las entradas
Mostrando entradas con la etiqueta Documentation. Mostrar todas las entradas
Fuente | Help Net Security |  ISO72001standard.com

Un equipo de expertos liderados por Dejan Kosutic, han elaborado un conjunto de unos 37 documentos en Ingles, Español y Croata, bajo el titulo de "Kit de documentación ISO 27001 (ISO 27001 Documentation toolkit)", que sirven para la implantación del estandar ISO/IEC 27001 "Information technology - Security techniques - Information security management systems - Requirements" y son perfectamente válidos para ser presentado en el examen de certificación de la empresa en ISO 27001.

Los documentos están especialmente dirigidos a pequeñas y medianas empresa, donde las exigencias y requisitos de seguridad son menores. Cada documento se ha elaborado añadiendo comentarios y consejos sobre cada uno de los apartados, sin perder de vista la "adaptación" a las necesidades de cada Organización.

No debe olvidarse que este "juego de plantillas" puede ser gran utilidad a la hora de generar la documentación necesaria para llevar a cabo la implantación de la ISO 27001, aunque se recomienda adaptar en función de las necesidades de cada organización.

Los documentos han sido elaborados en formato Microsoft Word 97 - 2003 y MS Excel 97 - 2003, y pueden adquirirse de manera individual o en conjunto.

El precio 599$ - ISO 27001 Documentation Kit.






NOTA: Puesto que en la implementación de la ISO 27001 no se contempla (no obligatorio) la inclusión de los planes de continuidad de negocio, se recomienda consultar la siguiente documentación (BS 27999).
CISCO has developed the following technical document for strong network security based on his security framework, the Cisco Security Framework (CSF).

Now I'm going to share with all of you a brief introduction of the content of this paper.
What's Network Security Baseline?

This document is a support guide to strong network security based on CISCO Systems. This guide presents the fundamental network security elements that are key to developing a strong network security baseline, and it is designed to assist in this endeavour by outlining those key security elements that should be addressed in the first phase of implementing defense-in-depth.

The keys areas of security baseline:
  • Infrastructure Device Access
  • Routing Infrastructure
  • Device Resiliency and Survivability
  • Network Telemetry
  • Network Policy Enforcement
  • Switching Infrastructure
To prevent that default security settings become into a trouble, CISCO has developed this "security baseline" for hardening network facilitites in order to support network administrator in its labor.

In order to ensure a comprehensive solution, the Cisco Security Framework (CSF) is applied in the development of Network Security Baseline. CSF provides a comprehensive method of assessing and validating the security requirements of a system.

What's Cisco Security Framework?

The Cisco Security Framework (CSF) is a security operational process model aimed at ensuring network, and service, availability and business continuity. It is designed to identify current threat vectors through the use of best common practices and comprehensive solutions.

Cisco Security Framework (CSF).

Harden network infrastructure, isolate hosts and services, and enforce security policies. To achieve this total visibility and complete control, enforce network policy.

The Network Security Baseline presented may be used as a reference model during the initial assessment and gap analysis phases. It provides the minimum requirements for control and management protection. Strengths and weaknesses of real-world networks can be identified by comparing them against the baseline.

How to should I used this paper?

CISCO addresses the security configuration in each of key areas of security baseline matching with CSF Methodology. For each key areas the CSF Methodology is assessed and aplied where it highlight the technologies and features identified for baseline secure supported by Cisco IOS plattform.  In fact, all sample configurations in this paper are based on Cisco IOS platforms and features.

The follwing table is a sample of CSF Methodology assessment into "Infraestructure Device Access" area.

Table - Applying CSF Methodology in Infraestructura Device Access - Technology need to be hardening.

This is a great handbook for hardening a Network based on CISCO System, even you can get strong knwologedment in network security for applying in other devices.

If you are a network administrator and have something to do with Information Security, I highly recommend  you.