ISO-27000 (Revised in 2014) NIST SP800-53 (Revision 4 issued April 2014) SANS Top 20 Critical Security Controls UK 10 Steps to cyber security aspects of information security. It is a leading international authority on information risk management. ISO The International Organization for Standardization develops and publishes International Standards. NIST US National Institute for Standards and Technology The SANS Top 20 is now maintained by the Council on CyberSecurity, an independent, global non-profit entity committed to a secure and open Internet. UK Government This publication is the work of multiple UK government agencies: BIS, CPNI, GCHQ and the Cabinet Office. ISO-27000 is the international standard for Information Security. The ISO 27000 family of standards helps organizations keep information assets secure. http://www.iso.org/iso/ho me/store/catalogue_tc/c atalogue_detail.htm?csn umber=63411 ISO 27001 describes an information security management system (ISMS). One of a range of publications in the SP800 series, this describes Security and Privacy Controls for U.S. Federal Information Systems and Organizations. The Critical Security Controls focuses first on prioritizing security functions that are effective against the latest Advanced Targeted Threats, with a strong emphasis on "What Works". http://nvlpubs.nist.gov/n istpubs/SpecialPublicati ons/NIST.SP.80053r4.pdf http://www.sans.org/criti cal-security-controls This publication is aimed at the senior reader and sets out the most important topics to focus on first. It contains a mixture of technical and non-technical measures. Page 32 of 33 www.cto.int https://www.gov.uk/gove rnment/uploads/system/ uploads/attachment_dat a/file/73128/12-112010-steps-to-cybersecurity-executive.pdf

Select target paragraph3