<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>pcmexico.org &#187; Confidentiality</title>
	<atom:link href="http://pcmexico.org/tag/confidentiality/feed/" rel="self" type="application/rss+xml" />
	<link>http://pcmexico.org</link>
	<description>Technology in Mexico</description>
	<lastBuildDate>Fri, 30 Oct 2009 17:54:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Corporate Watchdog</title>
		<link>http://pcmexico.org/corporate-watchdog/</link>
		<comments>http://pcmexico.org/corporate-watchdog/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 17:37:23 +0000</pubDate>
		<dc:creator>mexico</dc:creator>
				<category><![CDATA[HARDWORK]]></category>
		<category><![CDATA[Technology News]]></category>
		<category><![CDATA[Business Environment]]></category>
		<category><![CDATA[Business Goals]]></category>
		<category><![CDATA[Business Unit]]></category>
		<category><![CDATA[Confidentiality]]></category>
		<category><![CDATA[Conversations]]></category>
		<category><![CDATA[Corporate Watchdog]]></category>
		<category><![CDATA[Corrective Measures]]></category>
		<category><![CDATA[Information Leakage]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Integrity]]></category>
		<category><![CDATA[International Standard Organization]]></category>
		<category><![CDATA[Isms]]></category>
		<category><![CDATA[Networked]]></category>
		<category><![CDATA[Objective]]></category>
		<category><![CDATA[Own Organization]]></category>
		<category><![CDATA[Plan Do Check Act]]></category>
		<category><![CDATA[Polices]]></category>
		<category><![CDATA[Security Management System]]></category>
		<category><![CDATA[Security Risk]]></category>
		<category><![CDATA[Umbrella]]></category>

		<guid isPermaLink="false">http://pcmexico.org/corporate-watchdog/</guid>
		<description><![CDATA[The need for information security in a business environment that is highly-networked is not at all arguable. Information, as we are aware of, is the most valuable asset in an enterprise. It needs to be consequently, protected as information leakage could become a liability. Information exists in different forms. It can be printed on a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://pcmexico.org/wp-content/uploads/informationsecurity.jpg"><img class="alignleft size-medium wp-image-116" style="margin: 5px 15px;" title="informationsecurity" src="http://pcmexico.org/wp-content/uploads/informationsecurity-300x261.jpg" alt="informationsecurity" width="300" height="261" /></a>The need for information security in a business environment that is highly-networked is not at all arguable. Information, as we are aware of, is the most valuable asset in an enterprise. It needs to be consequently, protected as information leakage could become a liability.</p>
<p>Information exists in different forms. It can be printed on a paper, electronically stored or transmitted, and can even be viewed in films or spoken in conversations. Whatever the form it takes or the means it is shared, information should always be protected.</p>
<p>Information has now been exposed to a growing number of threats. To effectively manage these risks, security management system should be established.</p>
<p>Information Security Management System (ISMS) is a set of polices concerning on the management of an information security risk. It also pertains to the rules, processes, practices, standards, structures and responsibilities that are empowered in an organization in order to protect the availability, confidentiality and/or integrity of the business’s and the client’s information with respect to the objective of the business. It is the umbrella under which the activities of a business or business unit are defined, organized, managed and monitored.</p>
<p>There are guidelines being set by the International Standard Organization (ISO) in order to implement effective and robust ISMS. One of this is the ISO/IEC27001 standard. This is a standard that describes an ISMS framework for implementing the policies on information security management. This basically adheres to the management process called P-D-C-A (Plan-Do-Check-Act).</p>
<p>•	Plan – plan to establish own organization’s ISMS.<br />
•	Do – implement and operate own ISMS.<br />
•	Check – maintenance and proper monitoring of ISMS are needed.<br />
•	Act – aim to continuously improve ISMS by providing preventive and corrective measures.</p>
<p>Having ISMS in an organization can be very beneficial not only to the company’s business goals but to the clients as well to whom the business is dealing with. Some of these benefits are:</p>
<p>•	Creation of structure and mechanism for enhanced decision-making<br />
•	Working hand in hand with the information security and the Corporate Policy<br />
•	Enabling business-friendly, risk-based management<br />
•	Faster information security program management<br />
•	An aid in the creation of better strategies, standards, roles and responsibilities<br />
•	Providing a more competitive edge among others<br />
•	Enhancement of corporate governance and compliance-related activities<br />
•	Efficiency of centralized distributed environments<br />
•	A tool for better classification, and protection of information in the business.</p>
<p>With the advent of these technology, managers and employees should not be complacent enough and not to put the entire load to the system. It is there to serve as a guide to everyone on how to be more vigilant and proactive in terms of dealing with very sensitive and critical information that might become a risk to the company’s goals and objectives. It is the employees’ responsibility to learn and adapt to the system and be able to know the risks that are involved in the information being passed around within the company’s premises. Therefore, they should be aware of the capability and the power of the ISMS.</p>
<p>Today, there are a lot of ISMS tools available on the market that an organization can choose from. These tools are designed to be compliant to the de facto standards set by the ISO.  These tools are either developed by companies who provide the above system such as the Integrated Security Management System, Inc. (ISMSi) and AVDAR ISMS. Alternatively, it could be custom-built by a certain company such as HP’s ISMS.</p>
<p>Depending on an organization’s need, they can always find a good source of ISMS tools and kits online. However, if a company wants to create their own ISMS committee then it is much better, since they can customize their system parallel to their goal. The ISO provides the guidelines and documents in creating effective ISMS.  With this, any company can have their own implementation of ISMS as long as they follow the rules and the policies.</p>
<p>Security&#8217;s awareness is important because it is a key factor in protecting the confidentiality, integrity, and availability of a corporation’s information system. Thus, information security is everyone’s responsibility, especially those who, in a day to day basis, interact and manage information resources. Establishing an effective ISMS therefore is a must.</p>
]]></content:encoded>
			<wfw:commentRss>http://pcmexico.org/corporate-watchdog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
