Business Benefits of ISSAF
It is the first framework to provide validation for bottom up security strategies such as penetration testing as well as top down approaches such as the standardization of an audit checklist for information policies.
History and Overview of ISSAF ISSAF is constantly evolving a framework that can model the internal control requirements for information security. By defining the tests along with the domains to be tested, it seeks to unify management policies with technical operations to ensure there is complete alignment between all levels in between. ISSAF covers major information technology platforms, most high level IT related operational processes, and is intended to be applicable to major industry verticals such as banking, manufacturing and services. This ubiquity of ISSAF is intended to ease it's adoption as the preferred security assessment framework by IT departments worldwide. In the process of this adoption OISSG seeks to position it as the basis for accrediting an organization's information security systems at the level of technical specifications that have been tried and tested by leading security practitioners worldwide. ISSAF version 0.2 is being released to the industry on the basis of extensive testing by a number of information security specialists working across the world, on different platforms for security assessments at organizations in different vertical markets. It is being released for use by organizations and assurance professionals, subject to appropriate open licensing terms.
|
CB Login
News
OISSG Wiki
ISSAF




