Contact HISPI for event and ticket information.

This event has ended!

View current events hosted by HISPI

HISPI Information Security Forum Series - Virtual

Thursday, September 30, 2010 from 11:00 AM to 12:00 PM (ET)

HISPI Information Security Forum Series - Virtual

Ticket Information

Type End     Quantity
HISPI Forum ISO 27004 Ended Free  

Event Details

HISPI Security Forum

ISO 27004

Information technology — Security techniques ― Information security management — Measurement

 Moderator: Gary Sheehan; Director of GRC Services at ASMGi

Vice President of the HISP Institute 

Professionals tasked with managing the Information Security function are challenged on many fronts. Beyond keeping up with vulnerabilities, threats, and controls, making information security management a value proposition is a critical need for most organizations. Furthermore, the security strategy activity has exposed security management and metrics as areas where there is significant pressure to show a ROI (Return On Investment).

 

ISO 27004 was published in December 2009. It provides guidance on the development and use of measures and measurement for the assessment of the effectiveness of an implemented information security management system and controls, as specified in ISO 27001. The appendix of the document also suggests metrics which were selected to align with ISO 27002.

 

It is intended to help an organization establish the effectiveness of its ISMS implementation, embracing benchmarking and performance targeting within the PDCA cycle.

 

The standard has the following key sections:

 

·         Information security measurement overview;

·         Management responsibilities;

·         Measures and measurement development;

·         Measurement operation;

·         Data analysis and measurement results reporting;

·         Information Security Measurement Program evaluation and  improvement.

This is an open round table discussion.

Forum Objectives:

1.) High level overview of ISO 27004

2.) Discuss how to collect “base measures”, and then apply techniques and decision criteria to create “indicators” used for ISMS management purposes.

3.) Get the forums feedback and ideas on alternative techniques regarding metrics and monitoring an organizations ISMS.

When & Where


Conference Round Table
866-740-1260 PIN 923355 Web Access: www.readytalk.com. Access Code 9233555 Intl: +1 303-248-0285 PIN: 9233555


Thursday, September 30, 2010 from 11:00 AM to 12:00 PM (ET)


  Add to my calendar

Hosted By

HISPI



The Holistic Information Security Practitioner (HISP) Institute (HISPI) is an independent certification organization consisting of volunteers that are true information security practitioners, such as Chief Information Security Officers (CISOs), Information Security Officers (ISOs), Information Security Managers, Directors of Information Security, Security Analysts, Security Engineers and Technology Risk Managers from major corporations and organizations.

 

  • HISPIpromotes a holistic approach to information security program management by providing certification opportunities in information security, information assurance and governance.

     

     

  • HISPI focuses on international standards, best practices, and comprehensive frameworks for developing robust and effective information security programs.