KAZ Security SIG Questionnaire


please enter your name:
please indicate your primary work location: 290
182
Electranet
ETSA
Other:

Existing Knowledge/Skills:
Security ManagementNoneA littleA reasonable amountA lotExpert
Security ArchitectureNoneA littleA reasonable amountA lotExpert
Access Control SystemsNoneA littleA reasonable amountA lotExpert
Application DevelopmentNoneA littleA reasonable amountA lotExpert
Operations SecurityNoneA littleA reasonable amountA lotExpert
Physical SecurityNoneA littleA reasonable amountA lotExpert
CryptographyNoneA littleA reasonable amountA lotExpert
Network and Internet SecurityNoneA littleA reasonable amountA lotExpert
Business Continuity PlanningNoneA littleA reasonable amountA lotExpert
Law, Investigations, and EthicsNoneA littleA reasonable amountA lotExpert

I would like to learn/talk more about:
Security ManagementNot interestedMaybe a bitYes - perhapsDefinitely
Security ArchitectureNot interestedMaybe a bitYes - perhapsDefinitely
Access Control SystemsNot interestedMaybe a bitYes - perhapsDefinitely
Application DevelopmentNot interestedMaybe a bitYes - perhapsDefinitely
Operations SecurityNot interestedMaybe a bitYes - perhapsDefinitely
Physical SecurityNot interestedMaybe a bitYes - perhapsDefinitely
CryptographyNot interestedMaybe a bitYes - perhapsDefinitely
Network and Internet SecurityNot interestedMaybe a bitYes - perhapsDefinitely
Business Continuity PlanningNot interestedMaybe a bitYes - perhapsDefinitely
Law, Investigations, and EthicsNot interestedMaybe a bitYes - perhapsDefinitely

My present commitments/interest level means that I would be able to regularly come to:
Can't attend meetings Once/Quarter Once/two months Once/month Irregularly/can't commit

any comments you would like to make:
or

Explanatory notes

Security Management Practices
Security management entails the identification of an organization's information assets, development of documentation, and implementation of policies with supporting standards, procedures, and guidelines.
Security Architecture and Models
The Security Architecture and Models domain contains the concepts, principles, structures, and standards used to design, monitor, and secure operating systems, equipment, networks, applications and those controls used to enforce various levels of availability, integrity, and confidentiality. Examples would include:
Access Control Systems and Methodology
Access controls are a collection of mechanisms that work together to create a security architecture to protect the assets of the information system. Examples would include:
Application Development Security
This domain addresses the important security concepts that apply to application software development. It outlines the environment where software is designed and developed and explains the critical role software plays in providing information system security. Examples would include:
Operations Security
Operations Security is used to identify the controls over hardware, media, and all persons with access privileges to any of these resources. Examples would include:
Physical Security
The physical security domain provides protection techniques for the entire facility, from the outside perimeter to inside office space, including all of the information system resources. Examples would include:
Cryptography
The cryptography domain addresses the principles, means, and methods of disguising information to ensure its integrity, confidentiality and authenticity. Examples would include:
Telecommunications, Network, and Internet Security
The telecommunications, network, and Internet security domain is a very large technical area. We will discusses a lot of detail including the:
Business Continuity Planning
The Business Continuity Plan (BCP) domain addresses the preservation and recovery of business operations in the event of outages.
Law, Investigations, and Ethics
The Law, Investigations, and Ethics domain addresses the spirit, intent, concept, and purposes of significant legal functions in the industry. It is important to understand which laws impact use of computers, jurisdiction, legal protocols, and proper forensic procedures.