CSA ISO/IEC TR 13335-1 : 2001
Superseded
INFORMATION TECHNOLOGY - GUIDELINES FOR THE MANAGEMENT OF IT SECURITY - PART 1: CONCEPTS AND MODELS FOR IT SECURITY
01-01-2001
10-01-2005
Foreword
Introduction
1 Scope
2 Reference
3 Definitions
4 Structure
5 Aim
6 Background
7 Concepts for the Management of IT Security
7.1 Approach
7.2 Objectives, Strategies and Policies
8 Security Elements
8.1 Assets
8.2 Threats
8.3 Vulnerabilities
8.4 Impact
8.5 Risk
8.6 Safeguards
8.7 Residual Risk
8.8 Constraints
9 Processes for the Management of IT Security
9.1 Configuration Management
9.2 Change Management
9.3 Risk Management
9.4 Risk Analysis
9.5 Accountability
9.6 Security Awareness
9.7 Monitoring
9.8 Contingency Plans and Disaster Recovery
10 Models
11 Summary
Provides the basic management concepts and models which are essential for an introduction into the management of IT security.
| DocumentType |
Standard
|
| PublisherName |
Canadian Standards Association
|
| Status |
Superseded
|
| Standards | Relationship |
| ISO/IEC TR 13335-1:1996 | Similar to |
| ISO 7498-2:1989 | Information processing systems — Open Systems Interconnection — Basic Reference Model — Part 2: Security Architecture |