| A senior engineer from Hewlett-Packard once told me | | | | such as service delivery, relationship management, |
| that the nice thing about standards was that you had | | | | resolution process, control processes, release |
| so many to choose from ... this is particularly true of | | | | processes, changed services and service |
| security standards. In this article I have reviewed the | | | | management. |
| main security standards and commented on their | | | | ISO/IEC 18028:2006 |
| applicability. | | | | This was developed to define a standard security |
| ISO/IEC 27001:2005 | | | | architecture that describes a framework to support |
| The ISO/IEC 27001:2005 standard covers all types of | | | | the planning, design and implementation of network |
| organisations and specifies the requirements for | | | | security. This standard had major contributions from |
| implementing, operating, monitoring, reviewing, | | | | the ITU X.805 standard. |
| maintaining and improving a documented Information | | | | PCI DSS 1.1:2006 |
| Security Management System (ISMS) and relates this | | | | The Payment Card Industry Data Security Standard |
| to the organisation's overall business risks. | | | | (PCI-DSS) includes requirements for security |
| ISO/IEC 20000:2005 | | | | management, policies, procedures, network |
| This standard was developed to reflect the best | | | | architecture, software design and other critical |
| practice guidance contained within the Information | | | | measures. It is designed to help reduce the frequency |
| Technology Infrastructure Library (ITIL) framework. It | | | | and impact of security incidents in the processing of |
| consists of two part: Specification for IT Service | | | | payment cards. PCI-DSS is applicable to any |
| Management and code of practice for service | | | | oragnisation that is processing card payments. |
| management. ITIL enables organisations to define a | | | | This is a brief review of four major security standards |
| model to manage their IT operations covering areas | | | | and their relevance to different types of organisation. |