วันศุกร์ที่ 7 กันยายน พ.ศ. 2550




Cyber security standards are security standards which enable organizations to practice safe security techniques in order to minimize the number of successful cyber security attacks. These guides provide general outlines as well as specific techniques for implementing cyber security. For certain specific standards, cyber security certification by an accredited body can be obtained. There are many advantages to obtaining certification including the ability to get cyber security insurance.
HistoryCyber security standards have been created recently because sensitive information is now frequently stored on computers that are attached to the internet. Also many tasks that were once done by hand are carried out by computer; therefore there is a need for Information Assurance (IA) and security. Cyber security is important to individuals because they need to guard against identity theft. Businesses also have a need for this security because they need to protect their trade secrets, proprietary information, and customer’s personal information. The government also has the need to secure their information. This is particularly critical since some terrorism acts are organized and facilitated by using the internet. One of the most widely used security standards today is ISO 17799 which started in 1995. This standard consists of two basic parts. BS 7799 part 1 and BS 7799 part 2 both of which were created by (British Standards Institute) BSI. Recently this standard has become ISO 27001. The National Institute of Standards and Technology (NIST) has released several special papers addressing cyber security. Three of these special papers are very relevant to cyber security: the 800-12 titled “Computer Security Handbook;” 800-14 titled “Generally Accepted Principals and Practices for Securing Information Technology;” and the 800-26 titled “Security Self-Assessment Guide for Information Technology Systems”.



ISO 17799Main article: ISO 17799ISO 17799 incorporates both parts of the BS 7799 standard. Sometimes ISO 17799 is referred to as BS 7799 part 1 and sometimes it refers to part 1 and part 2. BS 7799 part 1 provides an outline for cyber security policy; whereas BS 7799 part 2 provides a certification. The outline is a high level guide to cyber security. It is most beneficial for an organization to obtain a certification in order to be recognized as compliant with the standard. The certification once obtained lasts three years and is periodically checked by the BSI to ensure an organization continues to be compliant throughout that three year period. ISO 27001 (ISMS) replaces BS 7799 part 2, but since it is backward compatible any organization working toward BS 7799 part 2 can easily transition to the ISO 27001 certification process. There is also a transitional audit available to make it easier once an organization is BS 7799 part 2-certified for the organization to become ISO 27001-certified. ISO 17799 states that information security is characterized by integrity, confidentiality, and availability. The ISO 17799 standard is arranged into eleven control areas; security policy, organizing information security, asset mangement, human resources security, physical and environmental security, communication and operations, access controls, information systems acquisition/development/maintenance, incident handling, business continuity management, compliance.




Standard of good practiceMain article: Standard of Good PracticeIn the 1990s, the Information Security Forum (ISF) published a comprehensive list of best practices for information security, published as the Standard of Good Practice (SoGP). The ISF continues to update the SoGP every two years; the latest version was published in February 2007.
Originally the Standard of Good Practice was a private document available only to ISF members, but the ISF has since made the full document available to the general public at no cost.
Among other programs, the ISF offers its member organizations a comprehensive benchmarking program based on the SoGP.
NERC 1200. The newest version of NERC 1300 is called CIP-002-1 through CIP-009-1 (CIP=Critical Infrastructure Protection). These standards are used to secure bulk electric systems although NERC has created standards within other areas. The bulk electric system standards also provide network security administration while still supporting best practice industry processes. NISTMain article: NIST1) Special publication 800-12 provides a broad overview of computer security and control areas. It also emphasizes the importance of the security controls and ways to implement them. Initially this document was aimed at the federal government although most practices in this document can be applied to the private sector as well. Specifically it was written for those people in the federal government responsible for handling sensitive systems.
2) Special publication 800-14 describes common security principals that are used. It provides a high level description of what should be incorporated within a computer security policy. It describes what can be done to improve existing security as well as how to develop a new security practice. Eight principals and fourteen practices are described within this document.
3) Special publication 800-26 provides advice on how to manage IT security. This document emphasizes the importance of self assessments as well as risk assessments.
ISO 15408Main article: Common CriteriaThis standard develops what is called the “Common Criteria”. It allows many different software applications to be integrated and tested in a secure way.


Specail Topicslink น่าสนใจ เกี่ยวกับประกันภัยรถยนต์ ป.1
http://www.pkinsure.com/asia-insurance.htm
http://www.pkinsure.com/index1.htm
http://www.pkinsure.com/apply.htm
http://www.pkinsure.com/วิริยะประกันภัย.htm
http://www.pkinsure.com/อาคเนย์ประกันภัย.htm
http://www.pkinsure.com/msigประกันภัย.htm
http://www.pkinsure.com/ประกันภัยไทยวิวัฒน์.htm
http://www.pkinsure.com/นำสินประกันภัย.htm
http://www.pkinsure.com/เอเชียประกันภัย.htm
http://www.pkinsure.com/แอลเอ็มจีประกันภัย.htm
http://www.pkinsure.com/ไทยไพบูลย์ประกันภัย.htm
http://www.pkinsure.com/ชาร์ทิสประกันภัย.htm
http://www.pkinsure.com/กมลประกันภัย.htm
http://www.pkinsure.com/อินทรประกันภัย.htm
http://www.pkinsure.com/เมืองไทยประกันภัย.htm
http://www.pkinsure.com/ฟินิกซ์ประกันภัย.htm
http://www.pkinsure.com/ประกันคุ้มภัย.htm
http://www.pkinsure.com/มิตรแท้ประกันภัย.htm
http://www.pkinsure.com/คูเนียประกันภัย.htm
http://www.pkinsure.com/เทเวศประกันภัย.htm
http://www.pkinsure.com/บีทีประกันภัย.htm
http://www.pkinsure.com/เอราวัณประกันภัย.htm
http://www.pkinsure.com/เจ้าพระยาประกันภัย.htm
http://www.pkinsure.com/ไทยเศรษฐกิจประกันภัย.htm
http://www.pkinsure.com/ศรีเมืองประกันภัย.htm
http://www.pkinsure.com/ไทยศรีประกันภัย.htm
http://www.pkinsure.com/อลิอันซ์ซีพีประกันภัย.htm
http://www.pkinsure.com/สินมั่นคงประกันภัย.htm



http://www.aia-thailand.com
http://www.aia-thailand.com/aboutus.htm
http://www.aia-thailand.com/market.htm
http://www.aia-thailand.com/news.htm
http://www.aia-thailand.com/contact.htm
http://www.aia-thailand.com/career.htm
aia AIA เอไอเอ รับสมัครตัวแทนประกันชีวิต สมัครตัวแทนประกันตัวแทนประกันชีวิต รายได้พิเศษ งานประจำ งาน part time ธุรกิจส่วนตัว ประกันกลุ่ม ประกันสุขภาพ