Html/Javascript widget

Monday, 13 June 2016

Virtualisation Sprawl.

Virtualisation sprawl is a undesirable process that happens when the amount of virtual machines on a network becomes so huge that it's impossible to manage them effectively. Virtual machines might be created with ease,but having one entails the same level of responsability and compliance than a normal one. Among the measures taken by administrators to check virtualisation sprawl is standardising VM image files, while shelving Vms that are not being used to their full potential.
Virtual machine lifecycle management (VMLM) tools can help administrators oversee the implementation, delivery, operation and maintenance of virtual machines over the course of their existence. Such tools can furnish administrators with a dashboard user interface (UI) to display the virtual machines running on a network along with the physical machines hosting them and the proprietary licences installed on them.  

Saturday, 28 May 2016

IT controls

Information technology controls

IT controls are specific activities to ensure that business objectives are met. IT control objectives tie in to the core tenets of IT security, namely:  confidentiality, integrity and availability of data, serving as a valuable tool for the IT management of any business enterprise. The IT controls are performed by persons or systems and often come in two categories: IT general controls (ITGC) and IT application controls. ITGC include controls over the Information Technology (IT) environment, computer operations, access to programmes and data, programme development and programme changes. IT application gauges the processing of a transaction, checking for the accuracy of input-output routines.


IT General Controls (ITGC)

ITGC help ensure the reliability of data generated by IT systems to make sure that both their operation and output are reliable. The following types of control are common for ITGC:

Control environment -controls designed to shape the corporate culture or "tone at the top."
Change management procedures - controls designed to ensure the changes meet business requirements and are authorised.
Source code/document version control procedures - controls designed to protect the integrity of programme code
Software development life cycle standards - controls designed to ensure IT projects are effectively managed.
Logical access policies, standards and processes - controls designed to manage access based on business need.
Incident management policies and procedures - controls designed to address operational processing errors.
Problem management policies and procedures - controls designed to identify and address the root cause of incidents.
Technical support policies and procedures - policies to help users perform more efficiently and report problems.
Hardware/software maintenance - configuration, installation, testing, management standards, policies and procedures.
Disaster recovery/backup and recovery procedures - to enable continued processing despite adverse conditions.
Physical security - controls to ensure the physical security of information technology from individuals and from environmental risks.



IT application controls

These are fully automated to ensure that data are thoroughly processed with outright accuracy from input through output, also ensuring the privacy and security of transmitted data in the process. IT application controls may include the following:

Completeness checks - controls that ensure all records were processed from initiation to completion.
Validity checks - controls that ensure only valid data is input or processed.
Identification - controls that ensure all users are uniquely and irrefutably identified.
Authentication - controls that provide an authentication mechanism in the application system.
Authorisation - controls that ensure only approved business users have access to the application system.
Input controls - controls that ensure data integrity fed from upstream sources into the application system.
Forensic controls - controls that verify the logical accuracy of data based on input and output checksums.

IT controls and the CIO/CISO
The organisation's Chief Information Officer (CIO) or Chief Information Security Officer (CISO) is typically responsible for the security, accuracy and the reliability of the systems that manage and report all the company's data.

Internal control frameworks
COBIT (Control Objectives for Information Technology)
COBIT is a common framework for best practices in both IT general and application controls. Its basic premise is based on IT processes satisfying business requirements through specific IT control activities and the evaluation of said processes. The four COBIT major domains are: plan and organise, acquire and implement, deliver and support and monitor and evaluate.
 Another common framework is COSO (Committee of Sponsoring Organizations of the Treadway Commission), which uses five elements of internal control: control environment, risk assessment, control activities, information and communication and monitoring.

Monday, 23 May 2016

Hot site

A hot site is an off-premises location to allow a business to continue computer and network operations in the event of a computer or equipment disaster. A hot site has all the equipment necessary for a business to resume regular activities, including jacks for phones, backup data, computers and related peripherals. Hot sites can be part of a business continuity plan or disaster recovery plan, where plans and procedures are laid out in the event that normal business activities cannot go on as usual in the normal location.
If an enterprise's data center becomes inoperable, for instance, all data processing operations are moved to a hot site. A cold site is similar in concept but provides office space only, it's up to the  customer to provide and install all the equipment needed to resume operations. It takes longer to get an enterprise in full operation after the disaster when a cold site is used.

Saturday, 21 May 2016

Difference between contingency plan and contingency planning

A contingency plan is made for emergency response, backup operations and post-disaster recovery for information systems and IT facilities when an unexpected service interruption takes place. The objective of this plan is to lead to minimal impact upon normal operations service capacity in the event of damage to information systems or facilities in which they're stored. Crisis management is part of the contingency plan in that it describes the measures to be taken to manage unexpected occurrences 
in the operational environment. 

Contingency planning addresses how to keep a company's critical processes running if any disruption happens. It's how a company prepares its staff for emergency situations.  A major element to that preparation is envisioning all of the potential emergencies that could occur. If a scenario would be dire if it occurred, it is worth the time and resources to prepare for its realization. Businesses, governments and other organizations that employ contingency planning consider a range of scenarios that could affect their operations, aiming to be comprehensive in the scope of emergencies that they examine. Overlooking a possible category of emergency in the contingency planning phase can leave an organization poorly prepared when a crisis hits. A helpful analogy to helping visualise the importance of contingency planning is how you would react if your house suddenly caught fire. It might be tempting to think that the obvious answer is to gather all your belongings that can be savaged and make a run for it as fast as possible. However, it's wishful thinking in that it's a prediction based on what you would instinctively do should that happen. 


Nevertheless, an effective contingency planning can't work out on instinctive reaction alone. If anything, it's counterproductive to rely on knee-jerk reflexes alone while throwing caution and reason to the winds. In order to be best prepared when a fire starts, you should think of all the possible steps to be taken to ensure as much safety as possible while minimising material loss. This would include a series of procedures like ensuring that both the fire brigade's number and a handy phone are within reach for contact, placing fire extinguishers at strategic locations and becoming familiarised with operating them and deploying them quickly whenever applicable, placing exit signs in order to coordinate a safe escapade, making sure that emergency stairways are always unobstructed etc. The procedures might seem glaringly obvious from a reasonable standpoint, but in the heat of the moment it's easy to get caught in the conundrum and not do the most reasonable thing. Officially documenting a contingency planning helps prevent chaotic behaviour that might only exacerbate the trouble. Same applies to decreasing the damage done to an organisation's operations and information systems. Contingency planning also goes through a series of similar stages such as identification of critical processes, Business Impact Analysis,  plan development and documentation, training, testing and maintenance and update.   





Common steps for contingency planning. From <http://homeworkhelpexperts.blogspot.com.br/2011/07/steps-of-developing-contingency-plan.html>

Friday, 20 May 2016

Contingency Plan

A contingency plan is a plan devised for handling disasters, although any plan designed for any outcome any than the expected one can be said to be a contingency plan. Often referred to as plan B, it's applied for risks of great magnitude that would have wide reaching consequences for the business. It's often necessary to have a contingency plan in order to avoid the possibility of freeze-out that occurs when someone is faced with a situation previously thought of as unlikely to occur. A contingency plan describes not only how to prepare for disaster but also how one should act in the actual occurrence of one. It usually describes the tasks, responsibilities and competences assigned to the staff of an organisation. Devising an effective contingency plan includes a business impact analysis and assessment stage.

The seven-steps outlined for an IT contingency plan publication are:

1. Develop the contingency planning policy statement. A formal policy provides the authority and guidance necessary to develop an effective contingency plan.

2. Conduct the business impact analysis (BIA). The BIA helps identify and prioritize information systems and components critical to supporting the organization’s mission/business functions.

3. Identify preventive controls. Measures taken to reduce the effects of system disruptions can increase system availability and reduce contingency life cycle costs.

4. Create contingency strategies. Thorough recovery strategies ensure that the system may be recovered quickly and effectively following a disruption.

5. Develop an information system contingency plan. The contingency plan should contain detailed guidance and procedures for restoring a damaged system unique to the system’s security impact level and recovery requirements.

6. Ensure plan testing, training and exercises. Testing validates recovery capabilities, whereas training prepares recovery personnel for plan activation and exercising the plan identifies planning gaps; combined, the activities improve plan effectiveness and overall organization preparedness.

7. Ensure plan maintenance. The plan should be a living document that is updated regularly to remain current with system enhancements and organizational changes.


Reference:

ROUSE, Margaret. Contingency Plan. WhatIs.com Retrieved from <http://whatis.techtarget.com/definition/contingency-plan>.

Tuesday, 17 May 2016

ICA-AtoM

ICA stands for Council on Archives, while AtoM' is short for "Access to Memory". It's a fully web-based repository that supports both single and multi-repository implementations.. It is an open-source system built to streamlining archival workflow, enabling repositories to launch their collections online with minimal cost and effort. It supports multiple collection types in a user-friendly way according to best practices for accessability, making it flexible and customisable for both small and large companies alike.

As a project, ICA-AtoM is free, open-source software developed by Artefactual Systems in collaboration with the ICA Program Commission (PCOM) and a growing network of international partners.

Sunday, 15 May 2016

Booster Bag

A booster bag is a handmade bag used to shoplift, typically from retail stores, libraries, and any other location employing security detectors to deter theft. The booster bag can be an ordinary shopping bag, backpack, pocketed garment, or other inconspicuous container whose inside is lined with a special material, typically multiple layers of aluminium foil.

An item is placed inside the booster bag, which is in effect a Faraday cage. This provides electromagnetic shielding, with the result that electronic security tags inside the bag may not be detected by security panels in the detector antennas at the store exit.

Booster bags have been used by professional shoplifters for several years. Using them, a shoplifter can steal dozens of items with very little effort.

The name "booster bag" comes from "boost" in the slang sense of "shoplift."