22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

50 Lotus Security Handbook<br />

There are ways to mitigate the human factor risks, such as those we just<br />

described. These risk mitigation techniques are incorporated into most<br />

methodologies, including our sample methodology, all of which are discussed<br />

later in this chapter.<br />

2.1.4 Selecting a methodology<br />

2.2 ISO17799<br />

By now, it should be evident that using a security methodology is the best way to<br />

ensure organization-wide security and implement it properly.<br />

Thanks to a continual evolution and improvement of security practices, a number<br />

of established methodologies have been created, improved, and made available<br />

from vendors, as well as from standards bodies and international organizations.<br />

Each offers a specific approach for implementing enterprise-wide security.<br />

Depending on the particular security needs of the organization implementing<br />

security, one approach may seem more appropriate than another. It is for the<br />

reader to determine which one suits best the specific needs of the organization<br />

whose systems are to be secured. The goal of the present section and the<br />

subsequent ones is to provide an overview of some of these methodologies and<br />

a description of what their offer. With this in mind, let’s look at the first<br />

methodology, ISO17799.<br />

ISO17799 is produced by the International Organization for Standardization<br />

(ISO), which is a network of the national standards institutes of 146 countries, on<br />

the basis of one member per country, with a Central Secretariat in Geneva,<br />

Switzerland, that coordinates the system.<br />

ISO is a non-governmental organization: its members are not, as is the case in<br />

the United Nations system, delegations of national governments. Nevertheless,<br />

ISO occupies a special position between the public and private sectors. This is<br />

because, on the one hand, many of its member institutes are part of the<br />

governmental structure of their countries, or are mandated by their government.<br />

On the other hand, other members have their roots uniquely in the private sector,<br />

having been set up by national partnerships of industry associations.<br />

Therefore, ISO is able to act as a bridging organization in which a consensus can<br />

be reached on solutions that meet both the requirements of business and the<br />

broader needs of society, such as the needs of stakeholder groups like<br />

consumers and users.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!