MyMIS Levels of details Level 1 ISO/IEC 13335-1 GMITS: Concepts and Models Level 2 ISO/IEC 13335-2 GMITS: Managing and Planning IT World/Global Level 3 ISO/IEC 13335-3 GMITS: Techniques for the Management of IT • • • Level 4 ISO/IEC 13335-4 GMITS: Selection of Safeguards ISO/IEC 13335-5 GMITS: Management Guidance on Network ISO/IEC 14516: Guidelines for the Management of Trusted Third Parties Level 5 Jurisdiction and culture-specific documents (National IT Security guidance documents) • BS 7799 • Canadian Handbook on Information Technology (MG-9) • The NIST Handbook • MyMIS Level 6 Domain and application specific documents, Industry guides German IT Baseline Protection Manual IETF RFC 2196 Site Security Handbook ISO/TR 13569 Banking and Related Financial Services-Information Security Guidelines CEN/ENV 12924 Medical Informations & Security Categorisation and Protection for Healthcare systems • ISO/IEC 15947 IT Intrusion Detection Framework • • • • Nation/Organization Site/Domain ▼ Figure 1.1: Various Levels of Details of Standards and Documents Level 5 of the model Level 5 represents the three standards referred, i.e. BS 7799, the Canadian Handbook of Information Technology and the NIST. Documents under this group are categorised as jurisdictional and culture-specific. The MyMIS handbook is represented at this level. Level 6 of the model The standards within Level 6 are domain and application specific. Examples of such standards are the German IT Baseline Protection document, the IETF RFC 2196 Site Security Handbook, the ISO/TR 13569 on Banking and Related Financial Services, the CEN ENV 12924 on Medical Informatics: Security Categorisation and Protection Healthcare Systems and the ISO/IEC 15947 on IT Intrusion Detection Framework. 1.3 This handbook describes safeguards, operational and technical issues and legal implications Copyright MAMPU Handbook Coverage This handbook provides the necessary guidelines on ICT security management safeguards to enable implementation of minimal security measures. It discusses elements of management safeguard, common operational and technical issues, and legal implications. The appendices at the end of the handbook may be of use to users with templates on security policies, adherence compliance plan, strategic plan, incident reporting mechanism, checklists and procedures. Its capacity is advisory and where the information contained is superceded (changes in technology, processes, legal requirements, public expectation) the reader is advised to refer to current adopted best practices. Chapter 1 - 3

Select target paragraph3