Appendix 4 INTERNATIONAL STANDARDS AND GOOD PRACTICE GUIDES FOR CYBERSECURITY
Note that this table contains a selection of the better known publications but many others exist.
Name of standard
ASD Strategies to
Mitigate Targeted
Cyber Intrusions,
previously known as
the Top 35
Authority who developed the
standard
ASD
The Australian Signals
Directorate is part of the
Australian government.
Comment on the nature of the standard
URL
ASD claims that least 85% of the targeted cyber
intrusions that the ASD responds to could be
prevented by following the top 4 mitigation
strategies
http://www.asd.gov.au/in
fosec/top35mitigationstr
ategies.htm
BSI
Bundesamt für Sicherheit in
der Informationstechnik
(abbreviated BSI - in English:
Federal Office for Information
Security)
The aim of IT-Grundschutz is to achieve an
appropriate security level for all types of
information of an organisation. ITGrundschutz uses a holistic approach to this
process.
ISACA
A non-profit, global
membership association for IT
and information systems
professionals,
ISF
The Information Security
Forum is a not-for-profit
organisation that supplies
opinion and guidance on all
ISACA claims that COBIT 5 is the only business
framework for the governance and management
of enterprise IT.
(Revised Feb 2014)
The BSI ITGrundschutz
(Continuously revised)
COBIT 5
(Issued April 2012,
superseding COBIT
4.1)
ISF Standard of Good
Practice
(Revised in 2014 and
every year)
https://www.bsi.bund.de
/EN/Topics/ITGrundschu
tz/itgrundschutz_node.h
tml
and
https://www.bsi.bund.de
It offers extremely detailed requirements across a /EN/Publications/BSISta
range of documents
ndards/BSIStandards_n
ode.html
http://www.isaca.org/CO
BIT/
Updated annually, the Standard of Good Practice https://www.securityforu
for Information Security (the Standard) claims it m.org/
is the most comprehensive information security
standard in the world, providing more coverage of
topics than ISO.
Page 31 of 33
www.cto.int