翻訳と辞書
Words near each other
・ Standard model (disambiguation)
・ Standard Model (Exhibition)
・ Standard Model (mathematical formulation)
・ Standard molar entropy
・ Standard Mongolian
・ Standard monomial theory
・ Standard Moroccan Berber
・ Standard Motor Company
・ Standard Motor Products
・ Standard normal deviate
・ Standard normal table
・ Standard Occupational Classification System
・ Standard Occupational Listing
・ Standard of care
・ Standard of deferred payment
Standard of Good Practice
・ Standard of living
・ Standard of living in China
・ Standard of living in India
・ Standard of living in Israel
・ Standard of living in Japan
・ Standard of living in Pakistan
・ Standard of living in the United States
・ Standard of review
・ Standard of service
・ Standard of Ur
・ Standard Oil
・ Standard Oil (disambiguation)
・ Standard Oil Building
・ Standard Oil Building (Baltimore, Maryland)


Dictionary Lists
翻訳と辞書 辞書検索 [ 開発暫定版 ]
スポンサード リンク

Standard of Good Practice : ウィキペディア英語版
Standard of Good Practice

The Standard of Good Practice for Information Security, published by the Information Security Forum (ISF), is a business-focused, practical and comprehensive guide to identifying and managing information security risks in organizations and their supply chains.
The recently published 2011 Standard is the most significant update of the standard for four years. It includes information security 'hot topics' such as consumer devices, critical infrastructure, cybercrime attacks, office equipment, spreadsheets and databases and cloud computing.
The 2011 Standard is aligned with the requirements for an Information Security Management System (ISMS) set out in ISO/IEC 27000-series standards, and provides wider and deeper coverage of ISO/IEC 27002 control topics, as well as cloud computing, information leakage, consumer devices and security governance.
In addition to providing a tool to enable ISO 27001 certification, the 2011 Standard provides full coverage of COBIT v4 topics, and offers substantial alignment with other relevant standards and legislation such as PCI DSS and the Sarbanes Oxley Act, to enable compliance with these standards too.
The Standard is used by Chief Information Security Officers (CISOs), information security managers, business managers, IT managers, internal and external auditors, IT service providers in organizations of all sizes.
The 2011 Standard is available free of charge to members of the ISF. Non-members are able to purchase a copy of the standard directly from the ISF.
== Organization ==
The Standard has historically been organized into six categories, or ''aspects''. Computer Installations and Networks address the underlying IT infrastructure on which Critical Business Applications run. The End-User Environment covers the arrangements associated with protecting corporate and workstation applications at the endpoint in use by individuals. Systems Development deals with how new applications and systems are created, and Security Management addresses high-level direction and control.
The Standard is now primarily published in a simple "modular" format that eliminates redundancy. For example, the various sections devoted to security audit and review have been consolidated.
The six aspects within the Standard are composed of a number of ''areas'', each covering a specific topic. An area is broken down further into ''sections'', each of which contains detailed specifications of information security best practice. Each statement has a unique reference. For example, SM41.2 indicates that a specification is in the Security Management aspect, area 4, section 1, and is listed as specification #2 within that section.
The Principles and Objectives part of the Standard provides a high-level version of the Standard, by bringing together just the ''principles'' (which provide an overview of what needs to be performed to meet the Standard) and ''objectives'' (which outline the reason why these actions are necessary) for each section.
The published Standard also includes an extensive topics matrix, index, introductory material, background information, suggestions for implementation, and other information.

抄文引用元・出典: フリー百科事典『 ウィキペディア(Wikipedia)
ウィキペディアで「Standard of Good Practice」の詳細全文を読む



スポンサード リンク
翻訳と辞書 : 翻訳のためのインターネットリソース

Copyright(C) kotoba.ne.jp 1997-2016. All Rights Reserved.