Security Policies ProceduresThreat Vulnerability AssessmentRisk Assessment

Security Manual
Template

ISO 27000 - 27001 & 27002
(formerly ISO 17799),
Sarbanes Oxley, HIPAA,
PCI-DSS, and Patriot Act Compliant

 

Includes Audit Program for PCI DSS  Compliance, HIPAA Audit Guide, and ISO 27000 Checklist

Order Security Manual Template

The Security Manual for the Internet and Information Technology is over 240 pages in length. This electronic document is fully compliant with the ISO 27000 standard, Sarbanes Oxley, HIPAA standard, and the Patriot Act.

All versions of the Security Manual template include both the Business & IT Impact Questionnaire and the Threat & Vulnerability Assessment Tool (both were redesigned to address Sarbanes Oxley compliance.   In addition, the Security Manual Template PREMIUM Edition  contains detail job descriptions that apply specifically to security and Sarbanes Oxley. The job descriptions are:

  • Chief Security Officer (CSO)
  • Chief Compliance Officer (CCO)
  • VP Strategy and Architecture
  • Director e-Commerce
  • Database Administrator
  • Data Security Administrator
  • Manager Data Security
  • Manager Facilities and Equipment
  • Manager Network and Computing Services
  • Manager Network Services
  • Manager Training and Documentation
  • Manager Voice and Data Communication
  • Manager Wireless Systems
  • Network Security Analyst
  • System Administrator - Unix
  • System Administrator - Windows

Clients can also subscribe to Janco's Security Manual update service and receive all updates to the Security Manual Template. 

The template includes everything needed to customize the Internet and Information Technology Security Manual to fit your specific requirement.  The electronic document includes proven written text and examples for the following major topics for your security plan:

  • Compliance to ISO 27000 (27001 & 27002), HIPAA, SOX, PCI, and the Patriot Act
  • Security Manual Introduction - scope, objectives, general policy, and responsibilities
  • Risk Analysis - objectives, roles, responsibilities, program requirements, and practices program elements
  • Staff Member Roles - policies, responsibilities and practices
  • Physical Security  - area classifications, access controls, and access authority
  • Facility Design, Construction and Operational Considerations - requirements for both central and remote access points
  • Media and Documentation - requirements and responsibilities
  • Data and Software Security - definitions, classification, rights, access control, INTERNET, INTRANET, logging, audit trails, compliance, and violation reporting and follow-up
  • Network Security - vulnerabilities, exploitation techniques, resource protection, responsibilities, encryption, and contingency planning
  • Internet and Information Technology contingency Planning - responsibilities and documentation requirements
  • Travel and Off - Site Meetings - specifics of what to do and not do to maximize security
  • Insurance - objectives, responsibilities and requirements
  • Outsourced Services - responsibilities for both the enterprise and the service providers
  • Waiver Procedures - process to waive security guidelines and policies,
  • Incident Reporting Procedures - process to follow when security violations occur
  • Access Control Guidelines - responsibilities and how to issue and manage badges / passwords
  • Sample Forms

    • Business and IT Impact Questionnaire
    • Threat & Vulnerability Assessment Tool
    • Security Violation Reporting form
    • Security Audit form
    • Inspection Check List
    • New Employee Security form
    • Security Access Application form

Order Security Manual Template

 

 

 

Latest News


Cloud disaster recovery planning

May 2nd, 2016

Outsourcing TemplateMany companies now are including cloud disaster recovery process in their business continuity plans.   Janco has found that disaster plans that include the cloud if done well will simplify and  improve the success of the recovery process.

 Order Disaster Plan TemplateDisaster Plan Sample

Related posts:

  1. Disaster Recovery Plan in the cloud Paper disaster recovery and business continuity plans are difficult to keep up to date and be available for the recovery process. One solution that we...
  2. Top 10 Reasons Why Disaster Recovery Business Continuity Plans Fail In the recession many organizations put disaster recovery and business continuity on the back burner. As a result those plans are not as functional as...
  3. DRP BCP Best Practices Defined DRP BCP Best Practices Defined Here are some Disaster Recovery Business Continuity best practices   Keep your primary backup  disaster recovery business continuity data in...
  4. Radiological and Nuclear Disaster Planning ...
  5. Disaster Planning - Business Continuity Cost of No Plan Cost of no Plan CIO and the organizations they manage need to place a high value on being prepared for disasters of any kind because...
- more info

IT Job Market Poor at Best

April 5th, 2016

IT Job Market Poor at Best

U.S. employers added 3,800 new IT jobs in March, down from 9,300 in February, and 9,900 a year ago, the management consulting firm Janco Associates Inc. said, based on an analysis of a basket of IT-related jobs data released Friday by the U.S. Department of Labor's Bureau of Labor Statistics. Employers added 215,000 jobs across all sectors in March, down from 245,000 in February. Employers are expected to create only 72,000 more IT jobs by the end of the year, for a year- end total of roughly 91,000, said Janco Chief Executive M. Victor Janulaitis. That compares to a total of 112,000 jobs in 2015.

Mr. Janulaitis blames the downturn on political and economic uncertainties at home and abroad."All the hype of IoT and cloud-based applications is not translating into new IT jobs," says Mr. Janulaitis, who supplements the government data by interviewing CIOs directly. He says the mood among CIOs is less optimistic.

IT Hiring IT Job Descriptions IT Salary SurveyIT Salary SurveyJob Descriptions

- more info

Risk mitigation and service management

March 22nd, 2016

IT Service Management (ITSM) Service Oriented Architecture (SOA)

risk mitigation  and service managementMany IT professionals often overlook the usefulness of service management tools that they already have at their fingertips as a way to streamline and effectively manage internal risk processes.

IT Service Management for Service Oriented ArchitectureWhen a system defect or workplace disruption hits, you need to act fast to ensure the enterprise can continue to function, your employees and associates are informed and productivity is maintained . And where better to designate the first responder than your service - help desk with a focus on IT Service Management (ITSM).

ITSM Template Download Selected Pages  

- more info

Disaster Recovery more complex due to Microsoft

January 22nd, 2016

Disaster Recovery more complex due to Microsoft

10 commandments of business continuity planning

IT Service ManagementWith Microsoft's push to get everyone on Windows 10 they have made it more difficult for companies that have moved from Windows 7 and 8.  Those verions of the OS wiil not work on new PCs. 

IT Service Management - ITSM

Consider a disaster where PCs are damaged and new equipment is required.  All of applications and functions that have not been migrated to Windows 10 will be at risk.

Before that happens CIOs need to evalaute the risks they face due to this new Microsoft "full-of-fail "clarification" support policy.

ITSM Template Download Selected Pages  

- more info

Disaster and business continuity spending will remain flat in 2016

December 16th, 2015

Business continuity spending in 2016

Disaster and business continuity planningMost organizations are maintaining disaster recovery and business continuity spending levels. Janco reports that in 8%  of organizations business continuity spending will be ‘much higher’ in 2016 compared to 2015 and will be ‘higher’ in 26%. Half of all organizations will maintain business continuity spending at the same level in 2016 as it was in 2015.

Only in 11% percent of respondents will organizational business continuity spending would be lower in 2016 than in 2015.

 Order Disaster Plan Template Download Selected Pages

- more info

Business continuity after a disaster depends on communication

November 12th, 2015

DRP/BCP Security TemplatesWhen a CEO thinks Business Continuity, he thinks of the safeguards that should be in place ensuring business operations are not disrupted. However, due to the heavy dependency on Information Technology, a business leader's first priority is to have adequate data backups in order to enable recovery in case of a disaster or any loss of data, and to ensure that systems remain available 24x7.

Order DRP BCP SecuritySample DRP Security Manual

The right way to evaluate the quality of your system and data protection is to evaluate the Recovery Time Objective (RTO) and Recovery Point Objective (RPO). These metrics define how long you think it will take you to get back online and how current the data has to be.

All Business Continuity Disaster Recovery Planning efforts need to encompass how employees will communicate, where they will go and how they will keep doing their jobs. The details can vary greatly, depending on the size and scope of a company and the way it does business. For some businesses, issues such as supply chain logistics are most crucial and are the focus on the plan. For others, information technology may play a more pivotal role, and the Business Continuity Disaster Recovery Plan may have more of a focus on systems recovery.

Plan Do Act

- more info

CIOs are paid to lead

September 24th, 2015
A CIO is paid to lead. But it's difficult to do so when you don't have the right organizational structure in place. A house, after all, is only as strong as its foundation. So whether you're "the new guy" as a CIO or you've worked within your current position for a year or longer, you should carefully consider the following nine winning organizational moves to implement for your IT department. As compiled by Janco Associates, the best practices here aren't the stuff of rocket science (even if you happen to supervise a number of rocket scientists). Instead, they're a useful collection of suggestions that cover both the big picture, such as alignment with company-wide strategies, and the day-to-day, like assigning key roles to your employees. By putting the following in play, you'll find that you've covered many critical bases, including the need to delegate, develop talent, ensure business continuity, track tech trends and monitor the competition. Better yet: It's not an "all or nothing" list. You can adapt only one or two ideas and still take advantage of results. For more about Janco's list, click here. - See more at: http://www.cioinsight.com/it-management/leadership/slideshows/nine-ways-to-better-organize-your-it-department-08/#sthash.G89cO1jc.dpuf
A CIO is paid to lead. But it's difficult to do so when you don't have the right organizational structure in place. A house, after all, is only as strong as its foundation. So whether you're "the new guy" as a CIO or you've worked within your current position for a year or longer, you should carefully consider the following nine winning organizational moves to implement for your IT department. As compiled by Janco Associates, the best practices here aren't the stuff of rocket science (even if you happen to supervise a number of rocket scientists). Instead, they're a useful collection of suggestions that cover both the big picture, such as alignment with company-wide strategies, and the day-to-day, like assigning key roles to your employees. By putting the following in play, you'll find that you've covered many critical bases, including the need to delegate, develop talent, ensure business continuity, track tech trends and monitor the competition. Better yet: It's not an "all or nothing" list. You can adapt only one or two ideas and still take advantage of results. For more about Janco's list, click here. - See more at: http://www.cioinsight.com/it-management/leadership/slideshows/nine-ways-to-better-organize-your-it-department-08/#sthash.G89cO1jc.dpuf
A CIO is paid to lead. But it's difficult to do so when you don't have the right organizational structure in place. A house, after all, is only as strong as its foundation. So whether you're "the new guy" as a CIO or you've worked within your current position for a year or longer, you should carefully consider the following nine winning organizational moves to implement for your IT department. As compiled by Janco Associates, the best practices here aren't the stuff of rocket science (even if you happen to supervise a number of rocket scientists). Instead, they're a useful collection of suggestions that cover both the big picture, such as alignment with company-wide strategies, and the day-to-day, like assigning key roles to your employees. By putting the following in play, you'll find that you've covered many critical bases, including the need to delegate, develop talent, ensure business continuity, track tech trends and monitor the competition. Better yet: It's not an "all or nothing" list. You can adapt only one or two ideas and still take advantage of results. For more about Janco's list, click here. - See more at: http://www.cioinsight.com/it-management/leadership/slideshows/nine-ways-to-better-organize-your-it-department-09/#sthash.lWy9izzG.dpuf
A CIO is paid to lead. But it's difficult to do so when you don't have the right organizational structure in place. A house, after all, is only as strong as its foundation. So whether you're "the new guy" as a CIO or you've worked within your current position for a year or longer, you should carefully consider the following nine winning organizational moves to implement for your IT department. As compiled by Janco Associates, the best practices here aren't the stuff of rocket science (even if you happen to supervise a number of rocket scientists). Instead, they're a useful collection of suggestions that cover both the big picture, such as alignment with company-wide strategies, and the day-to-day, like assigning key roles to your employees. By putting the following in play, you'll find that you've covered many critical bases, including the need to delegate, develop talent, ensure business continuity, track tech trends and monitor the competition. Better yet: It's not an "all or nothing" list. You can adapt only one or two ideas and still take advantage of results. For more about Janco's list, click here. - See more at: http://www.cioinsight.com/it-management/leadership/slideshows/nine-ways-to-better-organize-your-it-department-09/#sthash.pF2ECXTa.dpuf

A CIO is paid to lead. But it's difficult to do so when you don't have the right organizational structure in place. A house, after all, is only as strong as its foundation. So whether you're "the new guy" as a CIO or you've worked within your current position for a year or longer, you should carefully consider the following nine winning organizational moves to implement for your IT department.

Order CIO Job Description

Highest Paid CIOs in publicly traded companies in 2012 as reported to the SEC in 2013

CIO Lenght of Employment

As compiled by Janco Associates (www.e-janco.com), the best practices here aren't the stuff of rocket science (even if you happen to supervise a number of rocket scientists). Instead, they're a useful collection of suggestions that cover both the big picture, such as alignment with company-wide strategies, and the day-to-day, like assigning key roles to your employees. By putting the following in play, you'll find that you've covered many critical bases, including the need to delegate, develop talent, ensure business continuity, track tech trends and monitor the competition. Better yet: It's not an "all or nothing" list. You can adapt only one or two ideas and still take advantage of results.

- more info

American Express hits privacy head on

September 2nd, 2015

American Express hits privacy head on with its "Privacy Center"

After many attack and phishing scams in the past year, American Express has come up with a proactive solution which is focused at provding an easy way for it customers to communicate with them. Customers can:

  • Explore your privacy choices and update communication preferences
  •  Review Privacy Notices and our Online Privacy Statement 
  • Learn how AMX protects customer privacy and keep thier information safe

Privacy readings

Privacy Policy, e-janco.com, Janco Associates, Janco
... Articles Archives Register CIO Roundtable Company Who we are Customers Downloads Advertizing Rate Sheet TestimonialsPrivacy Payment Options Terms and Conditions Return Policy Site Map Blog Top 10 Lists Privacy ...
URL: http://www.e-janco.com/privacy.htm
BYOD guidelines are defined
... Articles Archives Register CIO Roundtable Company Who we are Customers Downloads Advertizing Rate Sheet TestimonialsPrivacy Payment Options Terms and Conditions Return Policy Site Map Blog Top 10 Lists BYOD ...
URL: http://www.e-janco.com/Press/2013/20130510-BYOD-Policy.html
proposed privacy bill compliance nightmare
... Articles Archives Register CIO Roundtable Company Who we are Customers Downloads Advertizing Rate Sheet TestimonialsPrivacy Payment Options Terms and Conditions Return Policy Site Map Blog Top 10 Lists Compliance ...
URL: http://www.e-janco.com/Newsletters/2010/Compliance_Newsletter_100726.htm
Most business transactions and interactions between individuals and business are electronic
... Articles Archives Register CIO Roundtable Company Who we are Customers Downloads Advertizing Rate Sheet TestimonialsPrivacy Payment Options Terms and Conditions Return Policy Site Map Blog Top 10 Lists User ...
 
    

- more info

New job title - Chief Digital Officer - CDO

July 1st, 2015

The job of chief digital officer (CDO) has recently emerged as a new role on the leadership team, as organizations are looking to bring in digital capabilities and seeing the need for an executive with a new set of competencies that combines strategy, marketing, and technology. Many are considering hiring or have already hired a digital leader to oversee enterprisewide digital strategy.

Position Descriptions IT Salary Survey

263 IT Job Descriptions and Organization Charts

The Internet and IT Position Descriptions HandiGuide® was completed in 2014 and is over 700 pages; which includes sample organization charts, a job progression matrix, and 263 Internet and IT job descriptions.   The book also addresses Fair Labor Standards, the ADA, and is in a new easier to read format

BuyTable of Contents
- more info

Top 10 Cloud Security practices identified by Janco

May 26th, 2015

necessary security for the data and the application

Outsourcing Template

10 Cloud Security best practices have been identified by Janco.  They are more important today than ever before with the increase in the number of cloud applications and the number of hackers that are out there.

- more info