|
Abstract: . . . iso 17799 Page 1 Page 1 Copyright © 2003, Software Productivity Consortium NFP, Inc. 1 Understanding ISO 17799, Code of Practice for Information Security Management STC 2003 Bob Small, CISSP (small AT software DOT org) Bill Brykczynski, Ph.D. (bryk AT software DOT org) Software Productivity Consortium Copyright © 2003, Software Productivity . . . . . . http://webstore.ansi.org/ansidocstore/product.asp?sku= ISO/ IEC+1 7799:2000 – http://www.ceem.com/infosecurity_standards.asp • Auditor certification – http://www.irca.org/home.html Page 15 Page 15 Copyright © 2003, Software Productivity Consortium NFP, Inc. 29 Acronyms BS BSI CEO FERPA HIPAA IRCA ISMS ISO RAB ROC SPC UAE UK UKAS US British Standard British Standards Institution Chief Executive Officer Family Educational Rights and Privacy Act Health Information Portability and Accountability Act International Register of Certificated Auditors Information . . . . . . iso 17799 Page 1 Page 1 Copyright © 2003, Software Productivity Consortium NFP, Inc. 1 Understanding ISO 17799, Code of Practice for Information Security Management STC 2003 Bob Small, CISSP (small AT software DOT org) Bill Brykczynski, Ph.D. (bryk AT software DOT org) Software Productivity Consortium Copyright © 2003, Software Productivity Consortium NFP, . . . . . . “best practices” in information security Independent certification provides an unbiased endorsement of management due diligence Page 4 Page 4 Copyright © 2003, Software Productivity Consortium NFP, Inc. 7 Introducing ISO 17799 • ISO/ IEC 17799: 2000 Code of Practice for Information Security Management • Provides recommendations for information security management – Does not contain any requirements – Many recommendations supplemented by additional considerations – A starting point or reference model . . . . . . reference model • Provides a basis for inter-organizational security agreements – Trading partner agreements Copyright © 2003, Software Productivity Consortium NFP, Inc. 8 Scope of ISO 17799 10 Control Areas | 36 Control Objectives |127 Controls Best Practices 6. Communications and operations management 7. Access control 8. Systems development and maintenance 9. Business continuity management 10.Compliance 1. Security policy 2. Organizational security 3. Asset classification and control 4. Personnel . . . . . . ISMS ISO RAB ROC SPC UAE UK UKAS US British Standard British Standards Institution Chief Executive Officer Family Educational Rights and Privacy Act Health Information Portability and Accountability Act International Register of Certificated Auditors Information Security Management System International Standards Organization Registrar Accreditation Board Republic of China Software Productivity Consortium United Arab Emirates United Kingdom United Kingdom Accreditation Service United States . . . --3000,6,250,3174,15179
|
...downloading file:
Understanding ISO 17799, Code of Practice for Information Security ....PDF
from: www.systemsandsoftware.org
If download not starts automatically click here
|