|
Abstract: . . . certification and forms a useful a preface to other guidance documents in the scheme Guide to BS7799 Risk Assessment and Risk Management (PD3002) describes the underlying concepts behind BS7799 risk assessment and risk management, including terminology & process of assessing and managing risks based on the ISO /IEC Guidelines for the Management of IT Security (GMITS) Selecting BS7799 Controls (PD3005) describes the process of selecting appropriate controls Bug Me Email address: rossfraser@sextantsoftware.com Phone: (416) 960-5872 . . . . . . iso 17799 ISO 1779 A Minimum Standard for Maximum Security BCHIMPS Spring Education Session March 15, 2002 Ross Fraser Sextant Software Information Security Mgmt: Goals Context Threats, Vulnerabilities, Risks ISO 17799 Rationale History Current Use Structure of 17799 Steps to Implementation Limitations NHS ISO Toolkit Questions . . . . . . missing: digital signatures and non-repudiation no integration yet with ISO 15408 “Common Criteria” ISO JT1 SC 27 is actively reviewing objections and revising 17799 (revised edition expected shortly) Canadian experts on SC 27 are actively participating in review Limitations Additional/supplementary standards: Canadian Handbook on Information Technology Security developed by the Communications Security Establishment (CSE) ISO TR 13335 General Mgmt of IT Security (GMITS) ISO 15408 “Common Criteria” document for evaluating and rating security products ISO (D)TS 17090: Health Informatics – Public Key . . . . . . useful a preface to other guidance documents in the scheme Guide to BS7799 Risk Assessment and Risk Management (PD3002) describes the underlying concepts behind BS7799 risk assessment and risk management, including terminology & process of assessing and managing risks based on the ISO /IEC Guidelines for the Management of IT Security (GMITS) Selecting BS7799 Controls (PD3005) describes the process of selecting appropriate controls Bug Me Email address: rossfraser@sextantsoftware.com Phone: (416) 960-5872 . . . . . . iso 17799 ISO 1779 A Minimum Standard for Maximum Security BCHIMPS Spring Education Session March 15, 2002 Ross Fraser Sextant Software Information Security Mgmt: Goals Context Threats, Vulnerabilities, Risks ISO 17799 Rationale History Current Use Structure of 17799 Steps to Implementation Limitations NHS ISO Toolkit Questions Agenda Information . . . --3000,5,300,2679,15112
|