| Please note, that the Knowledge Base isn't translated to english completely at the moment. You will still find some german texts - we are translating permanently the outstanding parts! Thank you for understanding! |
Certification |
| |
|
|
standards and legal regulations |
The realisation of Security Governance can be guided by international standards and guidelines on the one hand, but you have to consider national law and regulations on the other hand. Because they have also tremendous influence on implementations of arrangements and countermeasures.
The most important standards are:
|
 |
|
|
|
more standards and norms |
Of course there are many more standards you will see in this field: TickIT; NIST 800-14 General accepted principles and practises for Securing Information Technology Systems; COSO Internal Control Integrated Framework; IFAC - International IT Guidelines; EnSEC - Enterprise Security Management, WebTrust, SysTrust, ITSEC - Information Technology Security Evaluation Criteria und Common Criteria for Information Technology Security Evaluation as predecessor of ISO / IEC 15408
|
|
|