Information about Cyber Security Standards
Cyber security standards are security standards which enable organizations to practice safe security techniques in order to minimize the number of successful cyber security attacks. These guides provide general outlines as well as specific techniques for implementing cyber security. For certain specific standards, cyber security certification by an accredited body can be obtained. There are many advantages to obtaining certification including the ability to get cyber security insurance.
Originally the Standard of Good Practice was a private document available only to ISF members, but the ISF has since made the full document available to the general public at no cost.
Among other programs, the ISF offers its member organizations a comprehensive benchmarking program based on the SoGP.
2) Special publication 800-14 describes common security principals that are used. It provides a high level description of what should be incorporated within a computer security policy. It describes what can be done to improve existing security as well as how to develop a new security practice. Eight principals and fourteen practices are described within this document. [4]
3) Special publication 800-26 provides advice on how to manage IT security. This document emphasizes the importance of self assessments as well as risk assessments. [5]
History
Cyber security standards have been created recently because sensitive information is now frequently stored on computers that are attached to the internet. Also many tasks that were once done by hand are carried out by computer; therefore there is a need for Information Assurance (IA) and security. Cyber security is important to individuals because they need to guard against identity theft. Businesses also have a need for this security because they need to protect their trade secrets, proprietary information, and customer’s personal information. The government also has the need to secure their information. This is particularly critical since some terrorism acts are organized and facilitated by using the internet. One of the most widely used security standards today is ISO 17799 which started in 1995. This standard consists of two basic parts. BS 7799 part 1 and BS 7799 part 2 both of which were created by (British Standards Institute) BSI. Recently this standard has become ISO 27001. The National Institute of Standards and Technology (NIST) has released several special papers addressing cyber security. Three of these special papers are very relevant to cyber security: the 800-12 titled “Computer Security Handbook;” 800-14 titled “Generally Accepted Principals and Practices for Securing Information Technology;” and the 800-26 titled “Security Self-Assessment Guide for Information Technology Systems”.ISO 17799
Standard of good practice
Originally the Standard of Good Practice was a private document available only to ISF members, but the ISF has since made the full document available to the general public at no cost.
Among other programs, the ISF offers its member organizations a comprehensive benchmarking program based on the SoGP.
NERC
NIST
2) Special publication 800-14 describes common security principals that are used. It provides a high level description of what should be incorporated within a computer security policy. It describes what can be done to improve existing security as well as how to develop a new security practice. Eight principals and fourteen practices are described within this document. [4]
3) Special publication 800-26 provides advice on how to manage IT security. This document emphasizes the importance of self assessments as well as risk assessments. [5]
ISO 15408
See also
- ISO 17799
- BS 7799
- NERC
- NIST
- Common Criteria
- Standard of Good Practice
- Information Security
- Information Assurance
- Intellectual Property
- Computer Security
- Computer Security Policy
References
- ^ 1.Department of Homeland Security, A Comparison of Cyber Security Standards Developed by the Oil and Gas Segment. (November 5, 2004)
- ^ 2.Guttman, M., Swanson, M., National Institute of Standards and Technology; Technology Administration; U.S. Department of Commerce., Generally Accepted Principles and Practices for Securing Information Technology Systems (800-14). (September 1996)
- ^ 3.National Institute of Standards and Technology; Technology Administration; U.S. Department of Commerce., An Introduction to Computer Security: The NIST Handbook, Special Publication 800-12.
- ^ 4.Swanson, M., National Institute of Standards and Technology; Technology Administration; U.S. Department of Commerce., Security Self-Assessment Guide for Information Technology Systems (800-26).
- ^ 5.The North America Electric Reliability (NERC). http://www.nerc.com. Retrieved November 12, 2005.
External links
- Information on ISO 17799
- NEWS about ISO 17799
- BS 7799 certification
- ISO webpage
- BSI website
- ISMS information
- ISMS International User Group
- NERC Standards
- NIST webpage
- The Information Security Forum (ISF)
- The Standard of Good Practice (SoGP)
- CYBER-ATTACKS! Trends in US Corporations
- Securing Cyberspace-Media
- DataCops - Digital Security Solution Provider
An organization (or organisation — see spelling differences) is a social arrangement which pursues collective goals, which controls its own performance, and which has a boundary separating it from its environment.
..... Click the link for more information.
..... Click the link for more information.
Cyber-warfare (also known as cybernetic war[1], or cyberwar) is the use of computers and the Internet in conducting warfare in cyberspace.[2]
..... Click the link for more information.
Types of attacks
..... Click the link for more information.
Computer security is a branch of information security applied to both theoretical and actual computer systems. Computer security is a branch of computer science that addresses enforcement of 'secure' behavior on the operation of computers.
..... Click the link for more information.
..... Click the link for more information.
ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 17799:2005
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 17799:2005
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 17799:2005
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 17799:2005
..... Click the link for more information.
..... Click the link for more information.
ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 17799:2005
..... Click the link for more information.
..... Click the link for more information.
The Standard of Good Practice (SoGP) is a detailed documentation of best practice for information security. First released in 1996, the Standard is published and revised biannually by the Information Security Forum (ISF), an international best-practices association
..... Click the link for more information.
..... Click the link for more information.
This article or section needs sources or references that appear in reliable, third-party publications. Alone, primary sources and sources affiliated with the subject of this article are not sufficient for an accurate encyclopedia article.
..... Click the link for more information.
..... Click the link for more information.
The Standard of Good Practice (SoGP) is a detailed documentation of best practice for information security. First released in 1996, the Standard is published and revised biannually by the Information Security Forum (ISF), an international best-practices association
..... Click the link for more information.
..... Click the link for more information.
The Standard of Good Practice (SoGP) is a detailed documentation of best practice for information security. First released in 1996, the Standard is published and revised biannually by the Information Security Forum (ISF), an international best-practices association
..... Click the link for more information.
..... Click the link for more information.
NERC may refer:
..... Click the link for more information.
- North American Electric Reliability Corporation
- Natural Environment Research Council
- Nashville & Eastern Railroad Corporation
- Northeast Robotics Club
- National equine rescue coalition
..... Click the link for more information.
NERC may refer:
..... Click the link for more information.
- North American Electric Reliability Corporation
- Natural Environment Research Council
- Nashville & Eastern Railroad Corporation
- Northeast Robotics Club
- National equine rescue coalition
..... Click the link for more information.
NERC may refer:
..... Click the link for more information.
- North American Electric Reliability Corporation
- Natural Environment Research Council
- Nashville & Eastern Railroad Corporation
- Northeast Robotics Club
- National equine rescue coalition
..... Click the link for more information.
NERC may refer:
..... Click the link for more information.
- North American Electric Reliability Corporation
- Natural Environment Research Council
- Nashville & Eastern Railroad Corporation
- Northeast Robotics Club
- National equine rescue coalition
..... Click the link for more information.
The National Institute of Standards and Technology (NIST), known between 1901–1988 as the National Bureau of Standards (NBS), is a non-regulatory agency of the United States Department of Commerce. The institute's mission is to promote U.S.
..... Click the link for more information.
..... Click the link for more information.
The Common Criteria (CC) is an international standard (ISO/IEC 15408) for computer security. Unlike standards such as FIPS 140-2, Common Criteria does not provide a list of product security requirements or features that products must contain.
..... Click the link for more information.
..... Click the link for more information.
The Common Criteria (CC) is an international standard (ISO/IEC 15408) for computer security. Unlike standards such as FIPS 140-2, Common Criteria does not provide a list of product security requirements or features that products must contain.
..... Click the link for more information.
..... Click the link for more information.
ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 17799:2005
..... Click the link for more information.
..... Click the link for more information.
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO/IEC 17799,
..... Click the link for more information.
..... Click the link for more information.
This article is copied from an article on Wikipedia.org - the free encyclopedia created and edited by online user community. The text was not checked or edited by anyone on our staff. Although the vast majority of the wikipedia encyclopedia articles provide accurate and timely information please do not assume the accuracy of any particular article. This article is distributed under the terms of GNU Free Documentation License.
Herod_Archelaus