MyMIS
Levels of details
Level 1
ISO/IEC 13335-1
GMITS:
Concepts and Models
Level 2
ISO/IEC 13335-2
GMITS: Managing and Planning IT
World/Global
Level 3
ISO/IEC 13335-3
GMITS: Techniques for the Management of IT
•
•
•
Level 4
ISO/IEC 13335-4 GMITS: Selection of Safeguards
ISO/IEC 13335-5 GMITS: Management Guidance on Network
ISO/IEC 14516: Guidelines for the Management of Trusted Third Parties
Level 5
Jurisdiction and culture-specific documents (National IT Security guidance documents)
• BS 7799
• Canadian Handbook on Information Technology (MG-9)
• The NIST Handbook
• MyMIS
Level 6
Domain and application specific documents, Industry guides
German IT Baseline Protection Manual
IETF RFC 2196 Site Security Handbook
ISO/TR 13569 Banking and Related Financial Services-Information Security Guidelines
CEN/ENV 12924 Medical Informations & Security Categorisation and Protection for
Healthcare systems
• ISO/IEC 15947 IT Intrusion Detection Framework
•
•
•
•
Nation/Organization
Site/Domain
▼
Figure 1.1: Various Levels of Details of Standards and Documents
Level 5 of the model
Level 5 represents the three standards referred, i.e. BS 7799, the Canadian
Handbook of Information Technology and the NIST. Documents under this
group are categorised as jurisdictional and culture-specific. The MyMIS
handbook is represented at this level.
Level 6 of the model
The standards within Level 6 are domain and application specific. Examples
of such standards are the German IT Baseline Protection document, the
IETF RFC 2196 Site Security Handbook, the ISO/TR 13569 on Banking and
Related Financial Services, the CEN ENV 12924 on Medical Informatics:
Security Categorisation and Protection Healthcare Systems and the ISO/IEC
15947 on IT Intrusion Detection Framework.
1.3
This handbook describes
safeguards, operational
and technical issues and
legal implications
Copyright MAMPU
Handbook Coverage
This handbook provides the necessary guidelines on ICT security management
safeguards to enable implementation of minimal security measures. It discusses
elements of management safeguard, common operational and technical issues,
and legal implications. The appendices at the end of the handbook may be
of use to users with templates on security policies, adherence compliance
plan, strategic plan, incident reporting mechanism, checklists and procedures.
Its capacity is advisory and where the information contained is superceded
(changes in technology, processes, legal requirements, public expectation)
the reader is advised to refer to current adopted best practices.
Chapter 1 - 3