Information Security Harmonization

Marzo 2005 | Security
0503-securityguidance ISACA International annuncia la pubblicazione del rapporto “Information Security Harmonisation: Classification of Global Guidance” che contiene la descrizione ed il confronto dei principali standard e guideline relativi alla sicurezza informatica.
Il rapporto tiene conto anche dei risultati di un survey effettuato da ISACA tra i sui CISM,  Certified Information Security Manager, sui temi degli standard di sicurezza.

Il rapporto può essere scaricato in formato pdf in forma completa per gli associati o in forma ridotta per i non associati.
È infine possibile acquistare il rapporto per 40 dollari da ISACA Bookstore.

Gli standard esaminati sono:
  1. BS 7799 Part 2:2002 Information Security Management Systems—Specification With Guidance for Use
  2. COBIT
  3. SSE-CMM® Systems Security Engineering—Capability Maturity Model 3.0
  4. GAISP Version 3.0
  5. The Standard of Good Practice for Information Security
  6. ISO/IEC 13335 Information Technology—Guidelines for the Management of IT Security
  7. ISO/TR 13569:1997 Banking and Related Financial Services—Information Security Guidelines
  8. ISO/IEC 15408:1999 and Common Criteria
  9. ISO/IEC 17799:2000 Information Technology— Code of Practice for Information Security Management
  10. Security Management
  11. NIST 800-12 An Introduction to Computer Security—The NIST Handbook
  12. NIST 800-14 Generally Accepted Principles and Practices for Securing Information Technology Systems
  13. NIST 800-18 Guide for Developing Security Plans for Information Technology Systems
  14. NIST 800-53 Recommended Security Controls for Federal Information Systems, Second Public Draft
  15. OCTAVE® Criteria Version 2.0 Networked Systems Survivability Program
  16. Guidelines for the Security of Information Systems and Networks and Associated Implementation Plan
  17. Manager’s Guide to Information Security