ISO-27000
(Revised in 2014)
NIST SP800-53
(Revision 4 issued
April 2014)
SANS Top 20 Critical
Security Controls
UK 10 Steps to cyber
security
aspects of information security.
It is a leading international
authority on information risk
management.
ISO
The International Organization
for Standardization develops
and publishes International
Standards.
NIST
US National Institute for
Standards and Technology
The SANS Top 20 is now
maintained by the Council on
CyberSecurity, an independent,
global non-profit entity
committed to a secure and
open Internet.
UK Government
This publication is the work of
multiple UK government
agencies: BIS, CPNI, GCHQ
and the Cabinet Office.
ISO-27000 is the international standard for
Information Security. The ISO 27000 family of
standards helps organizations keep information
assets secure.
http://www.iso.org/iso/ho
me/store/catalogue_tc/c
atalogue_detail.htm?csn
umber=63411
ISO 27001 describes an information security
management system (ISMS).
One of a range of publications in the SP800
series, this describes Security and Privacy
Controls for U.S. Federal Information Systems
and Organizations.
The Critical Security Controls focuses first on
prioritizing security functions that are effective
against the latest Advanced Targeted Threats,
with a strong emphasis on "What Works".
http://nvlpubs.nist.gov/n
istpubs/SpecialPublicati
ons/NIST.SP.80053r4.pdf
http://www.sans.org/criti
cal-security-controls
This publication is aimed at the senior reader
and sets out the most important topics to focus
on first. It contains a mixture of technical and
non-technical measures.
Page 32 of 33
www.cto.int
https://www.gov.uk/gove
rnment/uploads/system/
uploads/attachment_dat
a/file/73128/12-112010-steps-to-cybersecurity-executive.pdf