Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: FIRM -framework fo risk assessment methodology implementation |
|---|---|
| Date: | Fri, 12 Nov 2004 15:30:07 -0500 |
The (excellent) Fundamental Information Risk Management (FIRM) methodology
is only licensed to members of the Information Security Forum (ISF)
<www.securityforum.org>. That's the only way to get it.
If you have it and are not a member organization, you are probably not
legally compliant and run the risks associated with copyright violation.
Unlike the free Standard of Good Practice, FIRM and other ISF tools and
publications are for Members only. That's one of the core benefits of
becoming a Member.
However, if you are an ISF member organization (or want to become one!),
FIRM implementation guidelines are available in the FIRM documentation
itself, through other Members via regional chapter meetings, or through
the on-line member forum, MX2. In addition, there are mature software
tools available to automate FIRM implementation, and some members may
provide FIRM consulting where appropriate.
As far as risk-management tools compliant with FIRM, the ISF has a whole
suite of "IRAM" and other tools developed to be compliant with one
another, including the FIRM framework and methodology.
-- Alan Willcox
The Vanguard Group
"The views expressed here are mine and do not reflect the official opinion
of my employer or the organization through which the Internet was
accessed."
"Ramiro Rodrigues" <ramiro.rodrigues@pobox.com>
11/10/2004 07:00 PM
Please respond to ramiro.rodrigues
To: <security-management@securityfocus.com>
cc:
Subject: FIRM -framework fo risk assessment methodology
implementation
Hi,
Does anybody have experience in implementing an I.T risk assessment
framework (tools and process) using FIRM methodology?
I need some basic guidelines in implementing it!
how to start?
Also, i need some indications of good IT risk managment tools (software)
that are "compliance"
with FIRM.
Please, let me know any information that could help me.
Thanks to everybody
Nikolas,
nikolas.rodrigues@terra.com.br
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Email Retention Policy, rainer |
|---|---|
| Next by Date: | Re: Email Retention Policy, Pramote Sritanon |
| Previous by Thread: | FIRM -framework fo risk assessment methodology implementation, Ramiro Rodrigues |
| Next by Thread: | Email Retention Policy, Robert Mezzone |
| Indexes: | [Date] [Thread] [Top] [All Lists] |