ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Download Now

The Simple Information Security Audit Process: SISAP

Did you find this white paper useful?


Publisher Pace University
Publisher Registration N/A
Topics Security Standards, Security Management, Best Practices Date added 01 Jun 2006
Downloads 65 Format 152.1KB PDF

The SISAP (Simple Information Security Audit Process) is a dynamic security audit methodology fully compliant with the ISO 17799 and BS 7799.2, and conformant with the ISO 14508 in terms of its functionality guidelines. The SISAP employs a simulation-based rule base generator that balances risks and business value generation capabilities using the Plan-Do-Check-Act cycle imposed in BS 7799.2. The SISAP employs a concept proof approach based on 10 information security best practices investigation sections, 36 information security objectives, and 127 information security requirements, as specified in the ISO 17799. The auditor may apply, for collecting, analyzing, and fusing audit evidence obtained at various audit steps, selected analytical models like certainty factors, probabilities, fuzzy sets, and basic belief assignments.

Download Now

Did you find this white paper useful?


  • Trackback
  • Clip Link

Related white papers

Accelerating Secure Business Applications Podcast

Download this Riverbed Connect podcast and listen as Bob Gilbert discusses with Mark Day, Riverbed's Chief Scientist, the details involving SSL encryption, SSL's impact on WAN optimization, and new wide-area...


Eroding Spam Filter Effectiveness: Bad for Business

As spammers and scammers continually introduce new and more sophisticated distribution techniques, organizations continue to see tremendous increases in spam and other email-borne threats--and the attacks are getting increasingly difficult...


Outbound Email and Data Loss Prevention in Today's Enterprise, 2008

How concerned are companies about the content of email leaving their organizations? And how do companies manage the legal and financial risks associated with outbound email? To find out, Proofpoint...


Extended Description Techniques for Security Engineering

There is a strong demand for techniques to aid development and modelling of security critical systems. Based on general security evaluation criteria, we show how to extend the system structure...


A Calculus for Cryptographic Protocols

We introduce the spi calculus, an extension of the pi calculus designed for describing and analyzing cryptographic protocols. We show how to use the spi calculus, particularly for studying authentication...


Trust Web Services and XML Security Standards

Web services are self-contained, modular applications that can be described, published, located, and invoked over the Internet. Web services perform well-defined functions both for applications and other Web services, which...


Critics Blast FCC Wiretap Specs

Sweeping standards announced by the Federal Communications Commission would make all common carriers, including cable operators and utilities offering telecommunications services, subject to a controversial 1994 digital wiretap law. Critics...


Featured White paper

IDC reports on Novell's Secure Desktop Solution: A Modern-Day Marriage of Business Benefit and Risk Reduction

The increasing mobility of the modern workforce and the competitive requirement to optimise that workforce with mobile communications has greatly increased the complexity of IT security. This IDC whitepaper examines how companies are turning to integrated security solutions, such as Novell Secure Desktop Solution, to deal with the vulnerability of mobile assets and implement a comprehensive security strategy.

Download Now

Other White Papers

Does 802.11n deliver better wireless services for Enterprises?

Watch our on demand 802.11n webinar to discover how HiPath Wireless 802.11n from Siemens Enterprise...

Farpoint Group report - 802.11n Access Points and POE: Key considerations

In this 5 page report, you'll discover more about the key technical considerations when making the...

See All White Papers