Forward
The Preparation of this book was fully funded by a grant from the infoDev Program of the World Bank Group.
The topic of Information Technology (IT) security has been growing in importance in the last few years, and
well recognized by infoDev Technical Advisory Panel. We would like to thank the State Secretariat of Economic
Affairs of Switzerland (SECO) for having been instrumental not only in providing the funding for this project, but
also in recognizing the urgency of the matter and allowing this book to come to fruition.
We recognize the fundamental role of Informational and Communication Technologies (ICT) for social and economic
development. Similarly, we recognize that there cannot be an effective use of ICT in the absence of a safe and
trusted ICT environment. Thus, IT security plays a prime role in helping creating the environment needed to set the
ground for implementing successful national ICT plans, e-Government or e-Commerce activities, as well as sectoral
projects, such as, for example, in the areas of education, health, or finance.
IT security is a complex topic and evolves almost as fast as technology does. The authors have succeeded in
providing technology-independent best practices, as well as recommendations for particular IT environments.
As technology evolves, the accompanying web site (www.infodev-security.net) will provide updates as appropriate,
allowing for a constant dissemination of developments in the field of IT security. While the opinions and recommen-
dations made in this book do not necessarily reflect the views of infoDev or The World Bank Group, we believe that
the combination of the book and its supporting web site will make a valuable contribution to the understanding of
IT security around the globe.
The book is composed of five parts, each of which can be read independently. After an introduction to general
issues of IT security, the book addresses issues relevant specifically to individuals, small and medium organizations,
government, and technical administrators. Although most of the research and publications on IT security comes
from developed countries, the authors have attempted to provide practical guidance applicable anywhere and to
include examples from developing countries.
We hope that this book and its supporting web site will provide the beginning of an interactive process, where the
content and best practices will evolve overtime as technology advances, but more importantly, as readers will share
their experiences and best practices with their peers.
Mohsen A. Khalil
Director, Global Information and Communication Technologies Department
The World Bank Group
Bruno Lanvin
Program Manager, infoDev Program
The World Bank Group
Michel H. Maechler
InfoDev Task Manager
Senior Informatics Specialist
The World Bank Group
Review Committee Members Information Technology Security Handbook
Walter Duss
Vice President,
swiss interactive media and software association (simsa)
Managing Director,
ASP Konsortium Switzerland
Wilen, Switzerland
Kurt Haering
President
EFSI AG
Basel, Switzerland
(Formerly President of Infosurance, Zurich, Switzerland)
Thomas Kellermann, CISM
Senior Data Risk Management Specialist
Financial Sector Operations & Policy Department
The World Bank
Washington, DC, USA
Werner Lippuner, CISA
Senior Manager,
Technology and Security Risk Services - Public Sector
Ernst & Young LLP
Washington, DC, USA
Bertrand Livinec, CISA
Practice Lead Sub-Saharan Francophone Africa Region
Group Risk Management Solutions (GRMS)
PriceWaterhouseCoopers
Paris, France
Michel Maechler, CISA, CISM
Senior Informatics Specialist
Global Information and Communications Technology, Policy Division
The World Bank
Washington, DC, USA
Scott Musman
President and CEO
Augmented Systems
Alexandria, VA, USA
(Formerly Director of Research and Development at IMSI)
David Satola
Senior Counsel
Finance, Private Sector Dvt, & Infrastructure
Legal Department
The World Bank
Washington, DC, USA
|