The Elsmar Cove Forum and Site Map The Elsmar Cove Wiki More Free Files The Elsmar Cove Forums Discussion Thread Index Post Attachments Listing Failure Modes Services and Solutions to Problems Elsmar cove Forums Main Page Elsmar Cove Home Page

Go Back   The Elsmar Cove Forum > Common Quality Assurance Processes and Tools > Software Quality Assurance


The Elsmar Cove Forum SideBar!
Monitor the Forum
Monitor New Forum Posts
New Threads Feeds
RSS FeedRSS Feed
Sponsor Link










$ Contributor Forum Access
Courtesy Quick Links

Links that Elsmar Cove visitors will find useful in your quest for knowledge:


Howard's International Quality Services

Atul's Symphony Technologies

Dave Scott's Scott Quality Solutions

Praxiom Research Group


NIST's Engineering Statistics Handbook

IRCA - International Register of Certified Auditors

SAE - Society of Automotive Engineers

Quality Digest Portal

IEST - Institute of Environmental Sciences and Technology

ASQ - American Society for Quality


All the Important Standards and Related Web Sites in the World
Reply
 
Thread Tools Search this Thread Rate Thread Content Display Modes
  #1  
Old 30th May 2003, 06:22 AM
Brian Dowsett Brian Dowsett is offline
$ Contributor

Registration Date: Apr 2002
Location: Waterford, Ireland
Age: 48
 
Posts: 20
Thanks Given to Others: 3
Thanked 1 Time in 1 Post
Karma Power: 32
Karma: 15
Brian Dowsett has less than 100 Karma points so far.
Question BS ISO/IEC 17799:2000 - Code of practice for information security management

Has anyone experience of ISO17799 ?

I've been asked to find out about it by my company.
All I know at the moment is that it's to do with software security.
Can you get audited by 3rd party?
Is it worth doing?
Will our customers be impressed?

Cheers

Brian
Reply With Quote

Sponsored Links
  #2  
Old 30th May 2003, 01:14 PM
Marc's Avatar
Marc Marc is online now
Your Elsmar Cove Host

Registration Date: Jan 1996
Location: West Chester, Ohio - USA
Age: 59
 
Posts: 15,859
Thanks Given to Others: 1,895
Thanked 1,568 Times in 1,020 Posts
Blog Entries: 4
Karma Power: 605
Karma: 11569
Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.
Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.
Send a message via AIM to Marc Send a message via Skype™ to Marc
Lurker

I've not heard of it before, but I did check it out and found this:

http://www.iso-17799.com

Welcome to the ISO 17799 Directory. Here you will find information covering the ISO 17799 standard itself, its contents, guidance on how to comply with it and details of resources to assist in this process.

What Is ISO 17799?

ISO 17799 is "a comprehensive set of controls comprising best practices in information security". It is essentially an internationally recognized generic information security standard.

Its predecessor, BS7799-1, has existed in various forms for a number of years, although the standard only really gained widespread recognition following publication by the International Standards Organization (ISO) in December 2000. Formal certification and accreditation were also introduced around the same time.

Contents? The standard comprises ten prime sections:

Business Continuity Planning
System Access Control
System Development and Maintenance
Physical and Environmental Security
Compliance
Personnel Security
Security Organization
Computer & Operations Management
Asset Classification and Control
Security Policy

Within these are the detailed statements that comprise the standard.

Compliance and Certification

The first step towards ISO17799 certification is of course to comply with the standard itself. This is of course is good security practice in itself, but it is also the longer term status adopted by a number of organizations, who require the assurance of external measure, yet do not wish to proceed with formal or external process.

In either case, the rigor enforced by the standard can be put to good use in terms of better management of risk. It is also being used in some sectors as a market differentiator, as organizations begin to quote their ISO 17799 status within their individual markets and to potential customers... another factor to ensure much wider uptake of the standard.
__________________
A Search is a terrible thing to waste!
One Test is Worth 1000 Expert Opinions - The plural of anecdote is not data.
We can't solve problems by using the same kind of thinking we used when we created them. - Unknown
Reply With Quote
Sponsored Links

  #3  
Old 30th May 2003, 03:49 PM
Atul Khandekar's Avatar
Atul Khandekar Atul Khandekar is offline
Forum Administrator

Registration Date: Mar 2000
Location: Pune, India
Age: 47
 
Posts: 1,073
Thanks Given to Others: 83
Thanked 84 Times in 55 Posts
Karma Power: 90
Atul Khandekar has disabled his/her Karma.
Send a message via Skype™ to Atul Khandekar
Default

Also check these:

http://www.iso17799software.com/

http://www.yourgateway.to/iso17799/

http://www.iso-17799-security-world.co.uk/
__________________
You are never given a wish without also being given the power to make it true. You may have to work for it, however. ~Richard Bach
Reply With Quote
  #4  
Old 29th July 2003, 04:16 AM
venkat venkat is offline
Involved - Posts

Registration Date: Feb 2002
Location: India/Chennai
Age: 42
 
Posts: 41
Thanks Given to Others: 1
Thanked 0 Times in 0 Posts
Karma Power: 32
Karma: 25
venkat has less than 100 Karma points so far.
Default Iso 17799/bs7799

BS7799 contains two parts I and II. BS7799 part I is now become part of ISO where as part I is not part of ISO. Organisations can be assessed for Part II. This is applicable for any type of organisations - IT and non-IT. There are ten domains of information security. I am a certifed implementer for BS7799. We are planning to implement in our organisation.
__________________
venkat
Reply With Quote
  #5  
Old 31st July 2004, 12:18 AM
udoryen udoryen is offline
Inactive Registered Visitor

Registration Date: Jul 2004
Location: Canada
 
Posts: 1
Thanks Given to Others: 0
Thanked 0 Times in 0 Posts
Karma Power: 22
Karma: 10
udoryen has less than 100 Karma points so far.
Default Iso17799

For more information about ISO17799/BS7799, you can download the following informations:
http://www.callio.com/files/wp_secura_en.pdf
https://www.callio.com/files/wp_iso_en.pdf
They're from Callio Technologies (www.callio.com), a software firm specializing in ISO17799/BS7799 software.
You can also visit a more neutral website at http://www.bs7799-iso17799.com.

Last edited by udoryen; 31st July 2004 at 12:20 AM.
Reply With Quote
  #6  
Old 3rd August 2004, 06:13 AM
venkat venkat is offline
Involved - Posts

Registration Date: Feb 2002
Location: India/Chennai
Age: 42
 
Posts: 41
Thanks Given to Others: 1
Thanked 0 Times in 0 Posts
Karma Power: 32
Karma: 25
venkat has less than 100 Karma points so far.
Default Security Objectives

The BS7799 standard specified security objectives which are measurable. I have checked many sites and I dont get any information.

Can anyone quote examples of measurable security objectives and also how they are measured.

I appreciate any website references for this
__________________
venkat
Reply With Quote
Reply

Lower Navigation Bar
Go Back   The Elsmar Cove Forum > Common Quality Assurance Processes and Tools > Software Quality Assurance

Bookmarks


Visitors Currently Viewing this Thread: 1 (0 Registered Visitors and 1 Unregistered Guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Forum Search
Display Modes Rate Thread Content
Rate Thread Content:

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Discussion Threads
Discussion Thread Title Thread Starter Forum Replies Last Post or Poll Vote
ISO 17799 and BS 7799 - Security Standards - ISMS is not a quality standard venkat Other ISO and International Standards and European Regulations 19 17th August 2006 10:45 AM
BS ISO/IEC 17799:2005 and ISO 27001:2005: Any advice on value and implementation? morgand Customer and Company Specific Requirements 4 11th July 2006 01:37 PM
BS 7799 and ISO 17799 document and records - Security Information Arte Records and Data - Quality, Legal and Other Evidence 12 24th April 2005 10:55 AM
ISO TR 10064-3 - Cylindrical gears - Code of inspection practice M Greenaway Inspection and Test, Sampling and Related Topics 3 2nd March 2004 10:40 PM



The time now is 02:02 AM. All times are GMT -4.
The time zone can be changed in your UserCP --> Options.



   

All Y'All Come Back Now, Y' Hear?

Made With A Mac! FreeBSD OS Powered by Apache!
Using php4 Forums provided and maintained by Marc Smith Database by MySQL

FAIR USE and CORRECTNESS NOTICE: This site contains copyrighted material the use of which has not always been specifically authorized by the copyright owner. We are making such material available in our efforts to advance understanding of environmental, political, human rights, economic, democracy, scientific, and social justice issues, etc. We believe herein constitutes a 'fair use' of any such copyrighted material as provided for in section 107 of the US Copyright Law. In accordance with Title 17 U.S.C. Section 107, the material on this site is distributed without profit to those who have expressed a prior interest in receiving the included information for research and educational purposes. For more information go to: http://www.law.cornell.edu/uscode/17/ If you wish to use copyrighted material from this site for purposes of your own that go beyond 'fair use', you must obtain permission from the copyright owner. In addition, I do not guarantee the correctness of the content. The risk of using content from the Elsmar Cove web site and forums remains with the user/visitor.

Responsibility Statement: Each person is responsible for anything they post in the Elsmar Cove forum. Neither I, Marc Timothy Smith, nor any of the forum Moderators, are responsible for the content of posts people make. Liability for post content resides with the poster as does interpretation and/or acceptance and/or use of advice by the reader.

Complaints: If you have a complaint with a post in a forum discussion thread, including Content in general, fighting, flaming, copyright infringement, defamation and/or 'slander', please use the 'Report This Post Report This Post Button button which appears at the top of every post in every thread.

Site courtesy of:
Marc Timothy Smith - Cayman Business Systems, 8466 Lesourdsville-West Chester Road, West Chester, Ohio 45069-1929 - USA
(513) 341-6272

To contact me, click the Google Voice link below, enter Your Name and Your Phone Number and Google will ring your phone and connect you for free!

The Elsmar Cove Web Site is *CopyFree*
no new posts