abegelid's picture
From abegelid rss RSS  subscribe Subscribe

June, 2007: Working in Iraq 

June, 2007: Working in Iraq

 

 
 
Tags:  Thanksgiving  itil practitioner 
Views:  64
Published:  January 31, 2012
 
0
download

Share plick with friends Share
save to favorite
Report Abuse Report Abuse
 
Related Plicks
Digital Signal Processing: A Practitioner's Approach

Digital Signal Processing: A Practitioner's Approach

From: anon-391657
Views: 220 Comments: 0
Digital Signal Processing: A Practitioner's Approach ,evansville in libraries, greene county library system, pricing of ebooks, flex dynamic image library
 
Treating Tourette Syndrome and Tic Disorders: A Guide for Practitioners

Treating Tourette Syndrome and Tic Disorders: A Guide for Practitioners

From: anon-389421
Views: 294 Comments: 0
Treating Tourette Syndrome and Tic Disorders: A Guide for Practitioners ,drake library jobs, baguio city public access library, faribault library, high school library smartboard lessons
 
Research Methods in Clinical Psychology: An Introduction for Students and Practitioners

Research Methods in Clinical Psychology: An Introduction for Students and Practitioners

From: anon-390813
Views: 254 Comments: 0
Research Methods in Clinical Psychology: An Introduction for Students and Practitioners ,gwinette county public library, compiling java function library, requirements for good ebook readers, 4.0 ajax library intregrated
 
Finding A Chiropractic Specialist Might Be Hard

Finding A Chiropractic Specialist Might Be Hard

From: Alma495Gaskell
Views: 19 Comments: 0

 
Nurse Practitioner Specialties Geared Towards Filling Needed Vacancies

Nurse Practitioner Specialties Geared Towards Filling Needed Vacancies

From: trafficmonsters
Views: 23 Comments: 0
Over the last decade, the range of nurse practitioner specialties have seen a subtle change in the paths these career nurses are choosing. In the past, graduates would choose to simply continue on in general medicine, often working in public health (more)

 
See all 
 
More from this user
teste

teste

From: abegelid
Views: 381
Comments: 0

Senior helpers in home elder care of spokane, washington, helps seniors avoid being swindled

Senior helpers in home elder care of spokane, washington, helps seniors avoid being swindled

From: abegelid
Views: 291
Comments: 0

Jasper Soft%20 Ap Is

Jasper Soft%20 Ap Is

From: abegelid
Views: 106
Comments: 0

progressive mreport-04/07

progressive mreport-04/07

From: abegelid
Views: 426
Comments: 0

Dali

Dali

From: abegelid
Views: 1618
Comments: 0

Datawise services

Datawise services

From: abegelid
Views: 245
Comments: 0

See all 
 
 
 URL:          AddThis Social Bookmark Button
Embed Thin Player: (fits in most blogs)
Embed Full Player :
 
 

Name

Email (will NOT be shown to other users)

 

 
 
Comments: (watch)
 
 
Notes:
 
Slide 1: Information Security Management Working in Iraq Bill Casti, CQA, SSCP, CISM, CISA, CITP, ITIL Foundations ASQ Section 0511 Northern Virginia 20 June 2007 1
Slide 2: Introduction • Position: Senior Advisor, IT Information Security Management, eGovernment Services, Economic Governance II Project What are all those letters? • • • • • • • CQA = ASQ Certified Quality Auditor SSCP = ISACA Systems Security Certified Practitioner CISA = ISC2 Certified Information Systems Auditor CISM = ISC2 Certified Information Security Manager CITP = British Computer Society Chartered IT Professional ITIL Foundations = passed IT Infrastructure Library Foundations exam 2
Slide 3: Quality Management in Iraq • • Short answer: There isn’t any. Longer answer: In order to build effective, consistent, repeatable, documented quality management, you need a stable infrastructure, and that’s not there in Iraq as a whole. Quality Management for this presentation: This slide show has been quality-managed by me, but I can’t tell you much about quality management in the Government of Iraq…there’s no formal or informal system for that. Someday maybe, but not today. • Day2Day working environment in Iraq for regular workers: Their big issue is getting to and from work alive. QMS kind of takes a backseat to that. • 3
Slide 4: Econ Gov II Project • • Project is USAID-funded Project was just picked up for both of its one-year extension options, runs thru September 2009 Project designed to help restore and rebuild economic governance for the Government of iraq • Project parameters include: Fiscal, Tax and Customs Reform; Monetary policy and Central Bank; Financial Reform; Commercial Law and Institutional Reform; Utilities/Regulatory Reform and Government-wide IT; Social Service and Pension Reform; General policy Implementation and Special Projects • 4
Slide 5: My TOR (Terms of Reference) Providing technical assistance to the Iraqi government in order to help them establish for their information requirements the legislation, processes, procedures, and technical requirements required to economically manage the resources, collection, storage, and sharing of information with the goal to provide: • •Transparency of Government • Increased access to Government • Decrease in discrimination • • • • • • Increase in commerce Increase in foreign investment Reduction in the cost of government Increased efficiency of government Increased security Private Sector participation 5
Slide 6: TOR (cont.) Tasks • Provide assistance to the National CIO Office: Establish Government-wide information security standards that comply with international best practice 1. a plan for implementing IT security standards across all Government Ministries 2.Establish 3.Build capacity and understanding of security standards 6
Slide 7: Expected Deliverables In conjunction with team members and the National CIO office develop Government wide IT security standards • • In conjunction with team members and the National CIO office develop a comprehensive IT security management capacity building program that covers o Security policy o Disaster recovery planning o Risk management o Securing the network o Intrusion detection, hacking o Computer forensics o Implementing PKI • Develop and conduct the following training seminars: o Disaster recovery planning o Securing the network o Risk management 7
Slide 8: Some Threats to Information Employees : who can you trust? • • • Unstable infrastructure Information transmission risks, both natural and manmade • • • • Verbal communications Printed documents Facility security Back-up sites 8
Slide 9: Information Security Management The ISO 17799 Way Safeguarding the confidentiality, integrity, and availability of written, spoken and computer information. 9
Slide 10: What is Information Security? BS ISO/IEC 17799:2005 defines this as: Confidentiality: ensuring that information is accessible only to those authorized to have access Integrity: safeguarding the accuracy and completeness of information and processing methods Availability: ensuring that authorized users have access to information and associated assets when required 10
Slide 11: Security for Advisors • Private security service is employed fulltime to take advisors to/from venues in the Red Zone • To Venues: • All Advisors wear body armor during any travel outside the IZ, covered with a dark-colored sweatshirt or casual shirt • Lead car is Level 4 armored, low-profile BMW or Mercedes that fits into the milieu of typical cars you see on the street; no big Chevy Suburbans or Ford Excursions with lots of flashing lights and military escorts; two armed guards in front, maximum of two advisors in back Trailing car is soft-side Nissan Altima or similar low profile car with two armed guards. • 11
Slide 12: Corporate Camp Living 12
Slide 13: Camp Living (cont.) 13
Slide 14: Camp Living (cont.) 14
Slide 15: Camp Living (cont.) 15
Slide 16: Camp Living (cont.) 16
Slide 17: Camp Living (cont.) 17
Slide 18: Camp Living (cont.) 18
Slide 19: Camp Living (cont.) 19
Slide 20: Thanksgiving 2006 20
Slide 21: Thanksgiving 2005 21
Slide 22: Traveling to/from the Airport 22
Slide 23: Science & Technology Counterparts Sundus Mousa Dr. Mahmood Sharief Director-General ITD 23
Slide 24: Red Zone Pics 24
Slide 25: Red Zone Pics 25
Slide 26: Red Zone Pics 26
Slide 27: Travel to/from BIAP 27
Slide 28: Baghdad international Airport 28
Slide 29: BIAP 29
Slide 30: Note ‘The relevance of any control should be determined in the light of the specific risks an organization is facing. Selection of controls should be based on a risk assessment.’ BS ISO/IEC 17799:2005 30
Slide 31: Controls for Best Practice • An Information Security Management Plan • Documented Roles and Responsibilities • Ongoing Information Security Education and Training • Ongoing Risk Assessments and Management of Risk • Reporting of Information Security Incidents and Events • Documented Disaster Recovery and Continuity of Business Operations Plans • Leveraging existing or off-the-shelf controls as needed to reduce labor and financial costs and to preclude “reinventing the wheel” 31
Slide 32: Customer and Other Contractual Requirement Considerations • Security Screening • Restricted Access • Physical perimeters • Data storage • Encryption • Digital signatures • Biometrics 32
Slide 33: Questions? 33
Slide 34: Contact Information Bill Casti, CQA, SSCP, CISM, CISA, CITP, ITIL Foundations eGovernment Services IT Advisor, eGovernment Services Iraq Economic Governance II Project BearingPoint +964 (0) 790.191.9612 Iraqna Mobile +1.703.879.5635 Skype VoIP Email: bill.casti@bearingpoint.com 34

   
Time on Slide Time on Plick
Slides per Visit Slide Views Views by Location