Search in ISMS Guides

Google
 

Tuesday, August 21, 2007

Data Recovery - What Can and Cannot be Recovered

1. The first method is to do it yourself. You turn on your computer and discover that the photographs you took on your holiday have been lost. It’s about time to think logically – either they have been overwritten or there has been surface contamination. In other cases, natural or man-made disasters like floods and fires may destroy important data. If you are an inexperienced computer user, then it is always advisable not to use your limited knowledge and try to reboot your computer to retrieve your data. But, on the other hand if you do boast of considerable computer expertise, you can retrieve your data using any data recovery tool available on your computer desktop. This involves:

  • Install the data recovery tool

  • Disconnect your computer

  • Install a new drive to save the retrieved data

  • Have a licence to run the data recovery tool


2. The second most common method is to call in the data recovery specialists. This is usually the case when you are unsure as to the cause of data loss. Data recovery agencies can recover 90% of your lost data, provided the loss is due to:

  • Accidental deletion of the data

  • Overwriting

  • Disk corruption

  • Reformatted, deleted volume or disk partition containing data

  • Partially damaged disk with bad spots caused by exposure to natural elements such as heat, light, water and dust


Data can be recovered from digital media files, memory sticks, ZIP files, hard drives, floppy diskettes and flashcards. Usually data recovery specialists can retrieve data by using two methods:

1. Physical Data Recovery which means retrieving the raw data from a damaged disk caused by a virus attack, operator system error or a natural disaster such as fire which may lead to surface contamination.

2. Logical Data Retrieval which refers to the rebuilding of lost data files. This type of data recovery becomes necessary when there is disk overwriting, reformatting and virus corruption.

According to data recovery agency, Disklabs, usually photographs and pictures including graphic material can be retrieved using physical data recovery methods. Usually nine out of every 10 photos are recovered in their original format. However, when database files are lost, retrieval is impossible. The experts at Disklabs claim that only 1% of database files are retrievable. In case of total data loss owing to natural disasters of fire and floods, experts recommend the installation of a backup drive away from the place of everyday use. Disklabs further argues that many universities and multinational corporations document vital information reducing sole dependency on digital media.

Other data recovery firms advocate the installation of a data recovery tool called Scavenger version 3. The advantage of using this tool lies in its function to scan an entire hard drive looking for corrupt and defunct volumes, partitions and spots. In this regard this tool is extremely good for novice users as it enables them not to lose new data while scanning the hard drive retrieving lost data. It is better than the computer desktop utility of CHECKDISK. But this data recovery tool cannot retrieve data entangled in the mesh of magnetised layers on the hard drive. Here, it becomes important to be aware of the time frame and cost of retrieving such data. Usually, experts using data recovery tools of Easy Recovery, Data Recovery and Data Advisor, state that it takes more than a working week to retrieve a mere .5% of the actual data. A prime example of data recovery can be seen at company Hewlett Packard which used its own technicians to retrieve a database file of employee records. In contrast, technicians at InfoUSA failed to retrieve vital editing material. In addition, they were unable to stop new data from being lost. As a result, an entire database file was lost.

It is very important to note that full data recovery is not possible. However, more than 95% of raw data can be recovered provided necessary steps to ensure recovery are undertaken in time. It simply does not do to wait for a few days before contacting a data recovery specialist agency. If you can’t do it, call them right away.

About the Author:

James Walsh is a freelance writer and copy editor. For more information on Data Recovery see http://www.fields-data-recovery.co.uk

Article Source: http://www.articlesbase.com/data-recovery-articles/data-recovery-what-can-and-cannot-be-recovered-159259.html

The Art of Data Recovery

You studied fine art, design, advertising, or perhaps you majored in business. Your computer is your productivity tool just as your grandparents regarded a pen and a pad of paper. But when something goes amiss with your “productivity tool”, your immediate concern is “Did I lose what I was working on? Can it be recovered?”

Have you ever found yourself in one of these predicaments?

* You were working on the client's ad campaign in your home studio revising creative on your personal Mac when suddenly the power went off. You waited a few moments in the dark. You started feeling stressed, so you lit up a smoke. Then the lights came back on but your computer did not. You lit up another smoke.

* You visited a site the boys at the pub were talking about the night before and downloaded some audio files. Now you can't access your spreadsheets containing this quarter's bookings and projected sales for the next fiscal year. To add insult to injury, you were scheduled to present the forecast to senior management in New York on Monday and had not backed up your system. You don’t even have a hardcopy of your number crunching.

* You and your companion laptop had occupied the spare office so you could work in solitude to put the finishing touches on your presentation to be delivered to the new client. Your co-worker then entered the room, slammed the door and bumped the table. You said goodbye to your coffee as well as your speaking notes and presentation. Or did you?

When the unthinkable happens and your data goes missing, it’s human nature to panic.

Unless you majored in computer science, you are probably not aware of the inner complexity of a hard disk drive that stores data. You simply regard your files—those customer records, spreadsheets, invoices, presentations, online storyboards, photographs, and more—-as your bread and butter, but to a data recovery expert they are “0’s” and “1’s” organized on your computer’s hard disk drive. If your hard drive is defective, the operating system on your computer infected or damaged by a virus, or files are deleted accidentally, access to the data is prevented.

If you take recovery measures into your own hands, care and caution should be exercised or your missing data could result in actual lost data. You could do more harm than good to your computer and data, if you attempt to perform a recovery on your own. It is your choice, but the consequences could result in unforeseen circumstances.

Yes, technology has come along way. However, there are several best practices that you can follow to significantly reduce the probability of losing your data:

* Regularly backup your data and test your backup

* Keep your computer in a dry, controlled environment free from dust and smoke

* Use anti-virus software and update it frequently to scan and screen all incoming data

* Turn off your computer if it or the hard drive makes an unusual noise.

* If you work for a small organization or work from a home office, play it safe. Use power surge protectors in the event your environment experiences a power outage.

* If your organization is large, ensure your backup and redundant storage systems are maintained offsite in a controlled environment

* Do not delay in taking appropriate action, if you cannot access your data. Ask and you shall receive help.

Data recovery is not an area in which computer science majors currently specialize and data loss is one of the computer industry’s most misunderstood concepts. That’s why it’s critical computer users avoid panic and attempts at misguided recovery efforts which can transform missing data into permanent lost data.

If you find yourself in such a predicament, get help.

If you require the assistance of a data recovery expert, don’t settle for second best. Sure, data recovery is about retrieving those “0’s” and “1’s”, but most importantly data recovery is about the quality of customer service you receive. From the time you place your panic-stricken telephone call seeking help until you have successfully downloaded your “missing” data, the communication between you and the data recovery firm is the catalyst for a successful data recovery. Deal with a data recovery organization where all employees—from the friendly receptionist who takes your initial call to the lab technician who is responsible for the recovery of your data--are empathetic to your needs. For here lies the true art of data recovery.

About the Author:

Bill Margeson, President and CEO of CBL Data Recovery Technologies.
Founded in 1993 and headquartered in Markham, Ontario, CBL Data Recovery Technologies Inc. is a leading international provider of data recovery services. CBL offers services worldwide through its network of data recovery laboratories, offices and authorized partners in Australia, Barbados, Brazil, Canada, China, Germany, Japan, Singapore, United Kingdom, and the United States.

Article Source: http://www.articlesbase.com/data-recovery-articles/the-art-of-data-recovery-176941.html

Are you Still not Backing Up your Data? - Microsoft

You should know this by now: Computers can and do fail. And nasty viruses can take down your system by creeping through your anti virus software and firewall.
The problem is that you usually get no warning before it's too late.
This has happened to many. In extreme cases, it has put companies out of business. And the worst part is this: It's completely avoidable. By backing up your data, you can retrieve all or most of what you lose.
Yes, there is a hassle involved. But you owe it to yourself — and your business — to take stock of your backup plan (or lack thereof) by reviewing these tips.

Most Important: Back up Your Customer Databases and Payroll Records

What's the heart and soul of your company? People have different opinions, but certainly your customer or client database has to rank high.

Inside one or two data files are all the nitty-gritty details including what they buy, when they buy, how they pay and so forth. Contact lists also are databases, and you might have yours combined with your customer list.
So, where would you be if you lost your database? How would you feel if you attempted to open your database and it wasn't there? Not good, I'll bet. So you should be backing up.
Also mission-critical for backups are your employee payroll records. You don't want to lose the information that you have to report to the tax department. Your employees don't want problems with them either. And they certainly don't want to be paid late.

Protect Your Registry Settings

You should be backing up all of your data. But if you don't, a third item you should have high on your priority list for regular backups is your Windows Registry. This is the huge database that tells your computer how to run. Without it, you have an expensive paperweight.
Most backup programs allow you to back up the Registry automatically. If not, you can easily do it manually. Here's how:
• Click Start > Run.

• In the box, enter "regedit" (without the quotes). Click OK.
• In the Registry, click File > Export (or Registry > Export Registry File in Windows 98). Navigate to your backup medium. It will probably be drive E:.
• Name the file and click Save.
You don't need to back up Windows or your applications, such as Microsoft Word. If the worst happens, you can always re-install them. But information you create must be protected.

Store Your Backups Off-Site

To really be safe, the backup medium (tape, CD or DVD, etc.) should be removed from your site. If you are backing up to tape, for instance, and you leave the tape cartridge in the machine, you'll be protected if the hard drive fails. But if the equipment is stolen, or the office burns to the ground, the backup will be lost.

The safest procedure is to use a different tape or disk each day. Keep all but the current day's backups off-site — at your home, perhaps.

Forget About Doing Backups with Floppies

The earliest backup medium was the floppy. These are no longer practical. They hold hardly any data, so a large collection would be needed for a backup. You would have to sit at the computer for hours, swapping the floppies in and out. Don't even think about it.
Tape has been the medium of choice for a number of years. Tapes are relatively slow, but the process can be automated. You can schedule the backup for when you're sleeping.
Tape drives and the tapes to go with them are relatively expensive, too. And the small business software can be difficult. Tape is a great backup medium, once you understand it. It has its drawbacks in terms of the time and work involved. But once you get a system running, it can go smoothly.
Here are some other options:
• Back up to a burner — a CD or DVD drive. Neither holds nearly as much data as a tape. If you decide to go this route, be sure your software allows automated backups. A CD or DVD will work well if your data is not voluminous. CDs will hold up to 700 MB; most DVDs will hold 4.7 GB.

• Use a Zip or Jaz drive. These are made by Iomega. Zips hold 250 MB of data; Jaz holds 2 GB.
• Use an external hard drive. These hold a vast amount of data. They attach to the computer via high-speed connections such as USB 2.0 or FireWire. Hard drives are fast, so the backup wouldn't take much time. But an external hard drive is relatively bulky, so you would get tired of taking it home.

Another Option to Consider: Backing up on an Internal Hard Drive

You could use a second internal hard drive, although that would mean leaving the backup in the office. Windows automatically accommodates multiple hard drives. You could simply copy your data from the master hard drive to the second one, known as a slave.
If having two hard drives appeals to you, consider a RAID system. RAID stands for Redundant Array of Inexpensive Disks. These systems can be complicated but a two-disk system is simple; you set it up as a mirror.
When you save something, it automatically saves to both drives. The second drive looks just like the first. So if one fails, you have a perfect copy. And RAID will automatically switch you over to the working drive.
Some motherboards have RAID capability built in. If yours doesn't, a RAID card can be added to the computer.
However, a RAID system would leave your backup inside the computer. That leaves you vulnerable to fire or theft.
Need More Security? Consider an Online Backup Service

If you're especially concerned about safety, you might want to consider an Internet backup. There are many firms on the web that will store your data for you, for a monthly fee. You can run the backup automatically.
Don't consider this route unless you have a high-speed internet connection. Backups by dial-up modem could tie up your phone lines for hours at a time.
Also, Microsoft SharePoint offers the ability to store copies of your most-vital business documents in a secure area that you can access through the Internet. SharePoint is available as part of Windows Server 2003.

About the Author:

Kim Komando writes about workplace technology and security issues. She's the host of the nation's largest talk-radio show about computers and the Internet, and writes a syndicated column for more than 100 Gannett newspapers and for USA Today.

Article Source: http://www.articlesbase.com/data-recovery-articles/are-you-still-not-backing-up-your-data-microsoft-171015.html

Use ISO 17799 to Improve Security and Minimize Risks

Most organizations are dependent upon their information and business systems, leaving them exposed to critical loss in the aftermath of a security breach. Fortunately, by implementing an information security management system ("ISMS"), as outlined in the only internationally accepted standard/code to address information security, a business can significantly reduce the risk of a security breach.

ISO/IEC 17799:2005 ("ISO 17799"), known as the Code of practice for information security management, was developed by an IT Security Subcommittee of the International Organization for Standardization and was published in June 2005. ISO 17799 is superior to other security standards because it is globally accepted and comprehensive. ISO 17799 has been cleverly crafted to work well across industries and geographies. Also, the International Organization for Standardization has consciously made this standard consistent with most other existing information security audit and control standards, such as those developed by the NIST (National Institute of Standards and Technology). Therefore, ISO 17799 can be the common framework that links to all other standards, regulatory requirements and corporate governance initiatives.

ISO 17799 provides practical guidelines for developing organizational security controls and effective security management practices. An ISO 17799 evaluation results in a snapshot of the company's security infrastructure, in that it provides a high-level view of how well (or how badly) a company implements information security. This standard is a great tool for companies whether establishing or improving information security within their organization.

The information security process traditionally has been based on sound best practices and guidelines, with the goals of preventing, detecting and containing security breaches, as well as restoration of the affected data to its previous state. While this cumulative wisdom of the ages is valid, it is also subject to various interpretations and implementations. ISO 17799 offers an achievable benchmark against which to build organizational information security.

Control Selection based on Risks Identified

ISO 17799 consists of 39 security controls, which can be used as a basis for a security risk assessment. The controls encompass all forms and types of information, whether they are electronic files, paper documents or various forms of communications such as email, fax and spoken conversations. The standard sets out a variety of hardware and software considerations, policies, procedures and organizational structures that protect a company's information assets from a broad range of modern security threats and vulnerabilities. How organizations shape their information security programs will depend on the unique requirements and risks they face. An organization should only deploy controls that relate to, and are in proportion to, the actual risks it faces.

Controls can also more simply be described as the countermeasures for risks. Apart from knowingly accepting risks considered acceptable, or transferring those risks (through insurance) to others, there are essentially four types of control:

1. Deterrent controls reduce the likelihood of a deliberate attack.
2. Preventative controls protect vulnerabilities and make an attack unsuccessful or reduce its impact.
3. Corrective controls reduce the effect of an attack.
4. Detective controls discover attacks and trigger preventative or corrective controls.

It is essential that any controls that are implemented are cost-effective. The cost of implementing and maintaining a control should be no greater than the identified and quantified cost of the impact of the identified threat (or threats). It is not possible to provide total security against every single risk; the trade-off involves providing effective security against most risks. No board should sign off on any ISMS proposal that seeks to remove all risk from the business - the business does, after all, exist within a risk framework and, since it is impossible to exist risk-free, there is little point in proposing to eliminate every risk.

No organization should invest in information security technology (hardware or software) or implement information security management processes and procedures without having carried out an appropriate risk and control assessment that assures them that:

- The proposed investment (the total cost of the control) is the same as, or less than, the cost of the identified impact;
- The risk classification, which takes into account its probability, is appropriate for the proposed investment; and
- Mitigating the risk is a priority - i.e. all the risks with higher prioritization have already been adequately controlled and, therefore, it is appropriate now to be investing in controlling this one.

Once information security needs and requirements are identified, a suitable set of controls from ISO 17799 can be established, implemented, monitored, reviewed and improved upon in order to ensure that the specific security objectives of the organization are met.

ISO 17799 is a comprehensive information security code of practice that provides enterprises an internationally recognized and structured methodology for information security. In addition to ISO 17799, the International Organization for Standardization also published ISO 27001, which specifies a number of requirements for establishing, implementing, maintaining and improving an ISMS using the controls outlined in ISO 17799.

ISO 27001 is the formal standard against which an organization may seek independent certification of their ISMS. While certification is entirely optional, as of January 2007, over 3000 organizations world-wide were ISO 27001 certified, demonstrating their commitment to information security. Organizations may be certified compliant with ISO 27001 by a number of accredited certification bodies worldwide. ISO 27001 certification generally involves a two stage audit process, with a "table top" review of key documentation at the first stage and a more in-depth audit of the ISMS at the second stage. The certified organization would need to be re-assessed periodically by the certification body.

In summary, organizations face threats to their information assets on a daily basis. At the same time, they are becoming increasingly dependent on these assets. Technical solutions are only one portion of a holistic approach to information security. Establishing broad information security requirements in the framework of the organization's own unique risk environment is essential.

About the Author:

Fazila Nurani is the President and Founder of PrivaTech Consulting (http://www.privatech.ca), based in Toronto, Canada. Visit Fazila Nurani's bio. Nurani advises organizations on compliance with global privacy laws and managing information security risks. She may be reached at +1.905.886.0751 or fazilanurani@rogers.com.

Article Source: http://www.articlesbase.com/non-fiction-articles/use-iso-17799-to-improve-security-and-minimize-risks-192347.html


Saturday, August 18, 2007

The Benefits of ISO 27001 Implementation

The benefits of standardization, and of implementation of one or more of the ISO 27000 series are wide and varied. Although they tend to differ from organization to organization, many are common.

The following is a list of potential benefits. As with many items on this website, this is an ongoing project. Please feel free to add further points via the comments option below.

Interoperability
This is a general benefit of standardization. The idea is that systems from diverse parties are more likely to fit together if they follow a common guideline.

Assurance
Management can be assured of the quality of a system, business unit, or other entity, if a recognized framework or approach is followed.

Due Diligence
Compliance with, or certification against, and international standard is often used by management to demonstrate due diligence.

Bench Marking
Organizations often use a standard as a measure of their status within their peer community. It can be used as a bench mark for current position and progress.

Awareness
Implementation of a standard such as ISO 27001 can often result in greater security awareness within an organization.

Alignment
Because implementation of ISO 27001 (and the other ISO 27000 standards) tends to involve both business management and technical staff, greater IT and Business alignment often results.

ISO 27001: Frequently asked questions

Information Security, ISMS, and ISO/IEC 27001 (BS 7799)

Risk Assessment and Risk Management

Certification

Implementing an Information Security Management System

There are key steps that every company implementing an Information Security Management System will need to consider:

Step1: Purchase the Standard
Before you can begin preparing for your application, you will require a copy of the standard. You should read this and make yourself familiar with it.

Step 2: Consider Training
There are training courses available to help you implement and assess your Information Security Management System.

Step 3: Assemble a team and agree your strategy
You should begin the entire implementation process by preparing your organizational strategy with top management. At this stage you should determine the Scope of your Registration - whether the system will be adopted company wide or by one or more departments.

Step 4: Review Consultancy Options
You can receive advice from independent consultants on how best to implement your information security management system.

Step 5: Undertake a Risk Assessment
During this phase you should undertake a review of all potential security breaches. This should not relate solely to IT systems, but should encompass all sensitive information within your organization.

Step 6: Develop a Policy Document
This will demonstrate management support and commitment to the Information Security Management System process.

Step 7: Develop Supporting Literature
Put together a Statement of Applicability and Procedures to support your security policy. This will cover a range of areas including asset clarification and control, personal security, physical and environmental security and business continuity management.

Step 8: Choose a registrar
The registrar is the 3rd party, like BSI, who come and assess the effectiveness of your information security management system, and issue a certificate if it meets the requirements of the standard. Choosing a registrar can be a complex issue as there are so many operating in the market. Factors to consider include industry experience, geographic coverage, price and service level offered. The key is to find the registrar who can best meet your requirements. A great place to start is by contacting us.

Step 9: Implement your Information Security Management System
The key to implementation is communication and training. During the implementation phase everyone begins operating to the procedures of the management system.

Step 10: Gain registration You should arrange your initial assessment with your registrar. At this point the registrar will review your Information Security Management System and determine whether you should be recommended for registration.

Step 11: Continual assessment
Once you have received registration and been awarded your certificate, you can begin to advertise your success and promote your business. Your ISMS will be periodically checked by your registrar to ensure that it continues to meet the requirements of the standard.

From : www.bsiamericas.com