Appendix 4 INTERNATIONAL STANDARDS AND GOOD PRACTICE GUIDES FOR CYBERSECURITY Note that this table contains a selection of the better known publications but many others exist. Name of standard ASD Strategies to Mitigate Targeted Cyber Intrusions, previously known as the Top 35 Authority who developed the standard ASD The Australian Signals Directorate is part of the Australian government. Comment on the nature of the standard URL ASD claims that least 85% of the targeted cyber intrusions that the ASD responds to could be prevented by following the top 4 mitigation strategies http://www.asd.gov.au/in fosec/top35mitigationstr ategies.htm BSI Bundesamt für Sicherheit in der Informationstechnik (abbreviated BSI - in English: Federal Office for Information Security) The aim of IT-Grundschutz is to achieve an appropriate security level for all types of information of an organisation. ITGrundschutz uses a holistic approach to this process. ISACA A non-profit, global membership association for IT and information systems professionals, ISF The Information Security Forum is a not-for-profit organisation that supplies opinion and guidance on all ISACA claims that COBIT 5 is the only business framework for the governance and management of enterprise IT. (Revised Feb 2014) The BSI ITGrundschutz (Continuously revised) COBIT 5 (Issued April 2012, superseding COBIT 4.1) ISF Standard of Good Practice (Revised in 2014 and every year) https://www.bsi.bund.de /EN/Topics/ITGrundschu tz/itgrundschutz_node.h tml and https://www.bsi.bund.de It offers extremely detailed requirements across a /EN/Publications/BSISta range of documents ndards/BSIStandards_n ode.html http://www.isaca.org/CO BIT/ Updated annually, the Standard of Good Practice https://www.securityforu for Information Security (the Standard) claims it m.org/ is the most comprehensive information security standard in the world, providing more coverage of topics than ISO. Page 31 of 33 www.cto.int

Select target paragraph3