Showing posts with label ISACA. Show all posts
Showing posts with label ISACA. Show all posts

Friday, November 16, 2012

Securing Mobile Devices Using COBIT 5 for Information Security

ISACA published (Members Only) guidelines for Securing Mobile Devices 

Securing Mobile Devices Using COBIT 5 for Information Security should be read in the context of the existing publications COBIT 5 for Information Security, Business Model for Information Security (BMIS) and COBIT 5 itself. This publication is intended for several audiences who use mobile devices directly or indirectly.

These include end users, IT administrators, information security managers, service providers for mobile devices and IT auditors. The main purpose of applying COBIT 5 to mobile device security is to establish a uniform management framework and to give guidance on planning, implementing and maintaining comprehensive security for mobile devices in the context of enterprises.

The secondary purpose is to provide guidance on how to embed security for mobile devices in a corporate governance, risk management and compliance (GRC) strategy, using COBIT 5 as the overarching framework for GRC.

Refer here to download. (Members Only)

Tuesday, May 15, 2012

Top 15 Paying IT Certifications According to Global Knowledge Training

Certifications are good for marketing and a necessary evil, but certainly not the be all/end all!


Global Knowledge Training LLC published a white paper outlining the top 15 paying IT certifications for 2012 based upon a survey they conduct annually. In the white paper, they don’t specify how they selected their sample for the survey; however they do maintain that the certifications and associated salaries were included only if there were at least 200 responses for that particular certification in the survey.


As such (and as the author points out), some certifications that do not have a large population in the work force (or that are more exclusive) may be inadvertently – and obviously – missing from this list (e.g., CCIE, VCDX, or OCSP).


Here are the results from the survey:


PMP - Project Management Professional $111,209
CISSP – Certified Information System Security Professional $110,342
CCDA – Cisco Certified Design Associate $101,915
ITIL v3 Foundation $97,691
MCSE – Microsoft Certified Systems Engineer $91,650
VCP – Vmware Certified Professional $91,648
CCNP – Cisco Certified Network Professional $90,457
CompTIA Server+ $84,997
MCITP – Microsoft Certified IT Professional $84,330
CCNA – Cisco Certified Network Associate $82,923
MCSA – Microsoft Certified Systems Administrator $82,923
CompTIA Security+ $80,066
MCP – Microsoft Certified Professional $79,363
CCENT – Cisco Certified Entry Network Technician $74,764
CompTIA Network+ $71,207


These results are based on US job market but you can use these figures as a benchmark or if you already have above certification, you can campre your salary with the US market.


MyCPEs.com is a free online tool built to help certified professionals manage and track their continuing education. Sign up for a free account now.

Saturday, August 13, 2011

Cloud computing guide to help enterprise increase value and manage risk

ISACA issued a new guide for implementing controls and governance

For all the talk of Cloud computing, the governance issue remains, for many enterprises, the great unknown. Cloud computing inevitably impacts business processes, making governance vital to managing risk and adapting to take advantage of new opportunities.

According to a survey of ISACA’s Australian members, less than half — 42 per cent — currently include Cloud computing strategies within their enterprise. And 80 per cent of these organisations limit Cloud computing to low-risk, non-mission-critical IT services.

Due diligence around the proposed service provider and appropriate controls must also be in place, she said, to ensure corporate information, is protected from loss, theft, tampering and loss of jurisdictional control.

Key questions for Cloud governance

ISACA’s guidance recommends enterprises ask the following key questions:
  • What is the enterprise’s expected availability?
  • How are identity and access managed in the Cloud?
  • Where will the enterprise’s data be located?
  • What are the Cloud service provider’s disaster recovery capabilities?
  • How is the security of the enterprise’s data managed?
  • How is the whole system protected from internet threats?
  • How are activities monitored and audited?
  • What type of certification or assurances can the enterprise expect from the provider?
ISACA will hold its Oceania CACS2011 conference to be held in Brisbane from 18-23 September, which will explore issues such as control, risk management, data loss prevention and assurance for Cloud strategies.