SoGP 2016 Exec Summary FINAL 260716
SoGP 2016 Exec Summary FINAL 260716
SoGP 2016 Exec Summary FINAL 260716
The ISF Standard of Good Practice for Information Security 2016 is the primary reference for information
security. Its practical and trusted guidance helps organisations to extract relevant good practice to underpin any
new initiative in your information security programme.
The Standard provides complete coverage of the topics set out in ISO/IEC 27002:2013, COBIT 5 for Information
Security, NIST Cybersecurity Framework, SANS Top 20 Critical Security Controls for Effective Cyber Defense and
Payment Card Industry Data Security Standard (PCI DSS) version 3.1.
ISF RESEARCH
BENCHMARK RESULTS
EXTERNAL DEVELOPMENTS
Security Architecture:
Navigating complexity
AWARENESS
Adopting the Standard reduces the need to
develop security awareness content from scratch.
The Standard covers topics that can be used to
improve security awareness and achieve expected
security behaviour amongst many dierent
audiences across an organisation, including
business users, technical sta, senior management,
systems developers and IT service providers.
It also addresses how information security should
be applied in local business environments that
typically require tailored awareness activities.
ISO/IEC 27001/2
COBIT 5 for Information Security
RISK ASSESSMENT
The Standards current and comprehensive content
when combined with the ISF Information Risk
Assessment Methodology 2 (IRAM2), can underpin
an organisations risk assessment process of
identifying business impacts, assessing key threats
and vulnerabilities, and treating information risks.
With this set of controls, an organisation can gain
eciency savings and deliver consistent protection
in line with their organisational risk appetite.
INFORMATION SECURITY
ASSESSMENT
Engaged Reporting:
Fact and fortitude
Threat Horizon 2017
IRAM2: The next generation
of assessing information risk
Maturity Model Assessments
MEMBER INPUT
Input from ISF Members, including workshops,
online collaboration on ISF Live, face-to-face
meetings, interviews and academy sessions at
the ISF Annual World Congress 2015 in
Atlanta, USA.
SECURITY ARRANGEMENTS
COMPLIANCE
The Standard is an ideal tool to help prepare for ISO/
IEC 27001:2013 certification, and achieve compliance
with other relevant standards (e.g., PCI DSS). It is aligned
with key information security standards in the ISO/IEC
27000 suite including security governance and supplier
relationships. The Standard covers hot topics not found in
ISO/IEC 27002 including cyber attack protection, system
decommission, enterprise mobility management and
industrial control systems.
WHERE NEXT?
The Standard of Good Practice for Information Security 2016 (the Standard) is the most comprehensive
and current source of information security controls. The Standard is updated on a biennial basis to
reflect the evolving international landscape of information securityrelated legislation and standards.
These updates include the latest findings from the ISFs research programme, input from our Member
organisations, trends from the ISF Benchmark and major external developments including new
legislation, changes in regulation and the releases of other information security-related standards.
Good practice described in the Standard will typically be incorporated into an organisations business
processes, information security policy, risk management and compliance arrangements. Consequently,
the Standard is valuable to a range of key individuals or external parties, including Chief Information
Security Officers (or equivalent), information security managers, business managers, IT managers and
technical staff, internal and external auditors, and IT service providers.
Consultancy services from the ISF provide Members and Non-Members with the opportunity to
purchase short-term, professional support activities to supplement the implementation of ISF
products including the Standard.
The Standard is available free of charge to ISF Members, and can be downloaded from the ISF
Member website www.isflive.org.
Non-Members interested in implementing the Standard or purchasing the report should contact
Steve Durbin at steve.durbin@securityforum.org.
CONTACT
For further information contact:
Steve Durbin, Managing Director
US Tel: +1 (347) 767 6772
UK Tel: +44 (0)20 3289 5884
UK Mobile: +44 (0)7785 953 800
Email: steve.durbin@securityforum.org
Web: www.securityforum.org
DISCLAIMER
This document has been published to provide general information only. It is not intended to provide advice of any kind. Neither the Information
Security Forum nor the Information Security Forum Limited accept any responsibility for the consequences of any use you make of the information
contained in this document.
Reference: ISF 03 04 16 | Copyright 2016 Information Security Forum Limited | Classification: Public, no restrictions