Voici quelques références qui aident dans les mesures en sécurité informatique.
Refs related to the measurement of security (KPIs, KRIs, KCIs)
- NIST SP800-55: Perf. Measurement Guide for Infosec (see Appendix A for examples)
- NIST SP800-53: Assessing Security Controls, Building Effective Security Assessment Plans
- NIST SP800-40: Section 3 – Security Metrics for Patch & Vulnerability Mgmt
- NIST Maturity Levels: High-level security program maturity
- ISO 27004:2009:
IT Security Techniques – Infosec Mgmt – Measurement – top-down &
bottom-up approach to security metrics, in line with other 27K standards
- ISO 21827:2008: IT Security techniques – Systems Security Engineering- Capability Maturity Model (SSE-CMM)
- Security Metrics: Replacing Fear, Uncertainty and doubt book
- DOD’s Measuring Security: published in 2009, compares NIST, ISO, ISACA… refers to other sources:
No comments:
Post a Comment