Tuesday, March 31, 2015

ISO standards for Information Security

ISO 15408:
International Standard that is used as the basis for the evaluation of security properties of products under the CC framework. It actually has three main parts:

ISO/IEC15408-1 Introduction and general evaluation model
ISO/IEC15408-2 Security functional components
ISO/IEC15408-3 Security assurance components

ISO/IEC 27799:
Guideline for information security management in health organizations.

ISO/IEC 27031:
Guidelines for information and communications technology readiness for business continuity.

BS 25999-1:
Business continuity management code of practice

BS 25999-2:
Specification for Business Continuity Management

ISO 22301:
This will replace BS 25999-2 and a standard for business continuity management systems.

ISO/IEC 42010:2007:
International Standard that provides guidelines on how to create and maintain system architecture.


No comments:

Post a Comment