ISO
Dates provided in the table below are based upon checking the ISO website 2004-09-08
ISO 216:1975
Writing paper and certain classes of printed matter - Trimmed sizes - A and B series
ISO 639-1:2002
ISO 639-2:1998
Codes for the representation of names of languages
— Part 1: Alpha-2 code
— Part 2: Alpha-3 code
ISO 1000:1992
and Amd 1:1998
SI units and recommendations for the use of their multiples and of certain other units
ISO/IEC 2382-1:1993
Information technology — Vocabulary — Part 1: Fundamental terms
ISO 2784:1974
Continuous forms used for information processing - Sizes and sprocket feed holes
ISO 2955:1983
Information processing - Representation of SI and other units for use in systems with limited character sets (Withdrawn)
ISO 3166-1:1997
ISO 3166-2:1998
ISO 3166-3:1999
Codes for the representation of names of countries and their subdivisions
— Part 1: Country codes
— Part 2: Country subdivision code
— Part 3: Code for formerly used names of countries
ISO 3535:1977
Forms design sheet and layout chart
ISO 4217:2001
Codes for the representation of currencies and funds
ISO 6346:1995
Freight containers - Coding, identification and marking
ISO 6422:1985
Layout Key for trade documents
ISO 8601:2004
Data elements and interchange formats - information interchange -representation of dates and times
ISO/IEC 8859-1:1998
ISO/IEC 8859-2:1999
ISO/IEC 8859-5:1999
ISO/IEC 8859-7:2003
Information processing - 8 bit single-byte coded graphic character sets-
Part 1: Latin alphabet No. 1
Part 2: Latin alphabet No. 2
Part 5: Latin/Cyrillic alphabet
Part 7: Latin/Greek alphabet
ISO 9735:2002-1/10
Electronic data interchange for administration, commerce and transport (EDIFACT) — Application level syntax rules
Showing posts with label Standards. Show all posts
Showing posts with label Standards. Show all posts
Wednesday, June 16, 2010
Wednesday, June 9, 2010
ISO 13485 Infrastructures requirements
ISO 13485 Infrastructures requirements
http://www.13485quality.com/resources-management/61-iso-13485-standrad-resource-management-requirement/122-iso-13485-infrastructures-requirements.html
The purpose of these requirements is to control any maintenance activities related to any infrastructures. Infrastructures are directly related to your product, therefore must be controlled. The purpose is to define how one should handle the infrastructure, during the realization process.
http://www.13485quality.com/resources-management/61-iso-13485-standrad-resource-management-requirement/122-iso-13485-infrastructures-requirements.html
The purpose of these requirements is to control any maintenance activities related to any infrastructures. Infrastructures are directly related to your product, therefore must be controlled. The purpose is to define how one should handle the infrastructure, during the realization process.
Thursday, May 20, 2010
The Canadian General Standards Board (CGSB)
The Canadian General Standards Board (CGSB)
http://www.tpsgc-pwgsc.gc.ca/ongc/home/index-e.html
The Canadian General Standards Board (CGSB) is a federal government organization that offers client-centred, comprehensive standards development and conformity assessment services in support of the economic, regulatory, procurement, health, safety and environmental interests of our stakeholders — government, industry and consumers.
http://www.tpsgc-pwgsc.gc.ca/ongc/home/index-e.html
The Canadian General Standards Board (CGSB) is a federal government organization that offers client-centred, comprehensive standards development and conformity assessment services in support of the economic, regulatory, procurement, health, safety and environmental interests of our stakeholders — government, industry and consumers.
Tuesday, February 23, 2010
Security Categorization
FIPS PUB 199
FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION
Standards for Security Categorization of Federal Information and Information Systems
http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf
Computer Security Division Information Technology Laboratory National Institute of Standards and Technology Gaithersburg, MD 20899-8900
February 2004
Security classification by impact and base on Confidentiality, impact, integrity, availability
POTENTIAL IMPACT DEFINITIONS FOR SECURITY OBJECTIVES
Page 1 notes:
Information is categorized according to its information type. An information type is a specific category of information (e.g., privacy, medical, proprietary, financial, investigative, contractor sensitive, security management) defined by an organization or, in some instances, by a specific law, Executive Order, directive, policy, or regulation.
Security Objectives:
The FISMA defines three security objectives for information and information systems:
CONFIDENTIALITY
“Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information...” [44 U.S.C., Sec. 3542]
A loss of confidentiality is the unauthorized disclosure of information.
INTEGRITY
“Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity...” [44 U.S.C., Sec. 3542]
A loss of integrity is the unauthorized modification or destruction of information.
AVAILABILITY
“Ensuring timely and reliable access to and use of information...” [44 U.S.C., SEC. 3542] A loss of availability is the disruption of access to or use of information or an information system.
Security Categorization Applied to Information Types
The security category of an information type can be associated with both user information and system information3 and can be applicable to information in either electronic or non-electronic form. It can also be used as input in considering the appropriate security category of an information system (see description of security categories for information systems below). Establishing an appropriate security category of an information type essentially requires determining the potential impact for each security objective associated with the particular information type.
The generalized format for expressing the security category, SC, of an information type is:
SC information type = {(confidentiality, impact), (integrity, impact), (availability, impact)}, where the acceptable values for potential impact are LOW, MODERATE, HIGH, or NOT APPLICABLE.4
EXAMPLE 1: An organization managing public information on its web server determines that there is no potential impact from a loss of confidentiality (i.e., confidentiality requirements are not applicable), a moderate potential impact from a loss of integrity, and a moderate potential impact from a loss of availability. The resulting security category, SC, of this information type is expressed as:
SC public information = {(confidentiality, NA), (integrity, MODERATE), (availability, MODERATE)}.
TERMS:
AVAILABILITY: Ensuring timely and reliable access to and use of information. [44 U.S.C., SEC. 3542] CONFIDENTIALITY: Preserving authorized restrictions on information access and disclosure,
including means for protecting personal privacy and proprietary information. [44 U.S.C., SEC. 3542]
SECURITY CATEGORY: The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on organizational operations, organizational assets, or individuals.
SECURITY CONTROLS: The management, operational, and technical controls (i.e., safeguards or countermeasures) prescribed for an information system to protect the confidentiality, integrity, and availability of the system and its information.
SECURITY OBJECTIVE: Confidentiality, integrity, or availability.
FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION
Standards for Security Categorization of Federal Information and Information Systems
http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf
Computer Security Division Information Technology Laboratory National Institute of Standards and Technology Gaithersburg, MD 20899-8900
February 2004
Security classification by impact and base on Confidentiality, impact, integrity, availability
POTENTIAL IMPACT DEFINITIONS FOR SECURITY OBJECTIVES
Page 1 notes:
Information is categorized according to its information type. An information type is a specific category of information (e.g., privacy, medical, proprietary, financial, investigative, contractor sensitive, security management) defined by an organization or, in some instances, by a specific law, Executive Order, directive, policy, or regulation.
Security Objectives:
The FISMA defines three security objectives for information and information systems:
CONFIDENTIALITY
“Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information...” [44 U.S.C., Sec. 3542]
A loss of confidentiality is the unauthorized disclosure of information.
INTEGRITY
“Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity...” [44 U.S.C., Sec. 3542]
A loss of integrity is the unauthorized modification or destruction of information.
AVAILABILITY
“Ensuring timely and reliable access to and use of information...” [44 U.S.C., SEC. 3542] A loss of availability is the disruption of access to or use of information or an information system.
Security Categorization Applied to Information Types
The security category of an information type can be associated with both user information and system information3 and can be applicable to information in either electronic or non-electronic form. It can also be used as input in considering the appropriate security category of an information system (see description of security categories for information systems below). Establishing an appropriate security category of an information type essentially requires determining the potential impact for each security objective associated with the particular information type.
The generalized format for expressing the security category, SC, of an information type is:
SC information type = {(confidentiality, impact), (integrity, impact), (availability, impact)}, where the acceptable values for potential impact are LOW, MODERATE, HIGH, or NOT APPLICABLE.4
EXAMPLE 1: An organization managing public information on its web server determines that there is no potential impact from a loss of confidentiality (i.e., confidentiality requirements are not applicable), a moderate potential impact from a loss of integrity, and a moderate potential impact from a loss of availability. The resulting security category, SC, of this information type is expressed as:
SC public information = {(confidentiality, NA), (integrity, MODERATE), (availability, MODERATE)}.
TERMS:
AVAILABILITY: Ensuring timely and reliable access to and use of information. [44 U.S.C., SEC. 3542] CONFIDENTIALITY: Preserving authorized restrictions on information access and disclosure,
including means for protecting personal privacy and proprietary information. [44 U.S.C., SEC. 3542]
SECURITY CATEGORY: The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on organizational operations, organizational assets, or individuals.
SECURITY CONTROLS: The management, operational, and technical controls (i.e., safeguards or countermeasures) prescribed for an information system to protect the confidentiality, integrity, and availability of the system and its information.
SECURITY OBJECTIVE: Confidentiality, integrity, or availability.
Minimum Security Requirements
Federal Information processing Standards
Minimum Security Requirements for Federal Information and Information Systems
http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf
FIPS PUB 200
FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION
3 MINIMUM SECURITY REQUIREMENTS
The minimum security requirements cover seventeen security-related areas with regard to protecting the confidentiality, integrity, and availability of federal information systems and the information processed, stored, and transmitted by those systems. The security-related areas include: (i) access control; (ii) awareness and training; (iii) audit and accountability; (iv) certification, accreditation, and security assessments; (v) configuration management; (vi) contingency planning; (vii) identification and authentication; (viii) incident response; (ix) maintenance; (x) media protection; (xi) physical and environmental protection; (xii) planning; (xiii) personnel security; (xiv) risk assessment; (xv) systems and services acquisition; (xvi) system and communications protection; and (xvii) system and information integrity. The seventeen areas represent a broad-based, balanced information security program that addresses the management, operational, and technical aspects of protecting federal information and information systems.
Specifications for Minimum Security Requirements
AccessControl(AC): Organizationsmustlimitinformationsystemaccesstoauthorizedusers,processes acting on behalf of authorized users, or devices (including other information systems) and to the types of transactions and functions that authorized users are permitted to exercise.
AwarenessandTraining(AT): Organizationsmust:(i)ensurethatmanagersandusersoforganizational information systems are made aware of the security risks associated with their activities and of the applicable laws, Executive Orders, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems; and (ii) ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.
AuditandAccountability(AU): Organizationsmust:(i)create,protect,andretaininformationsystemaudit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity; and (ii) ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.
Certification,Accreditation,andSecurityAssessments(CA): Organizationsmust:(i)periodicallyassessthe security controls in organizational information systems to determine if the controls are effective in their application; (ii) develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems; (iii) authorize the operation of organizational information systems and any associated information system connections; and (iv) monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.
2
FIPS Publication 200 Minimum Security Requirements for Federal Information and Information Systems
________________________________________________________________________________________________
ConfigurationManagement(CM): Organizationsmust:(i)establishandmaintainbaselineconfigurationsand inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; and (ii) establish and enforce security configuration settings for information technology products employed in organizational information systems.
ContingencyPlanning(CP): Organizationsmustestablish,maintain,andeffectivelyimplementplansfor emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations.
IdentificationandAuthentication(IA): Organizationsmustidentifyinformationsystemusers,processes acting on behalf of users, or devices and authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
IncidentResponse(IR): Organizationsmust:(i)establishanoperationalincidenthandlingcapabilityfor organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities; and (ii) track, document, and report incidents to appropriate organizational officials and/or authorities.
Maintenance(MA): Organizationsmust:(i)performperiodicandtimelymaintenanceonorganizational information systems; and (ii) provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.
MediaProtection(MP): Organizationsmust:(i)protectinformationsystemmedia,bothpaperanddigital;(ii) limit access to information on information system media to authorized users; and (iii) sanitize or destroy information system media before disposal or release for reuse.
Physical and Environmental Protection (PE): Organizations must: (i) limit physical access to information systems, equipment, and the respective operating environments to authorized individuals; (ii) protect the physical plant and support infrastructure for information systems; (iii) provide supporting utilities for information systems; (iv) protect information systems against environmental hazards; and (v) provide appropriate environmental controls in facilities containing information systems.
Planning(PL): Organizationsmustdevelop,document,periodicallyupdate,andimplementsecurityplans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing the information systems.
PersonnelSecurity(PS): Organizationsmust:(i)ensurethatindividualsoccupyingpositionsof responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions; (ii) ensure that organizational information and information systems are protected during and after personnel actions such as terminations and transfers; and (iii) employ formal sanctions for personnel failing to comply with organizational security policies and procedures.
Risk Assessment (RA): Organizations must periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information.
SystemandServicesAcquisition(SA): Organizationsmust:(i)allocatesufficientresourcestoadequately protect organizational information systems; (ii) employ system development life cycle processes that incorporate information security considerations; (iii) employ software usage and installation restrictions; and (iv) ensure that third-party providers employ adequate security measures to protect information, applications, and/or services outsourced from the organization.
3
FIPS Publication 200 Minimum Security Requirements for Federal Information and Information Systems
________________________________________________________________________________________________
SystemandCommunicationsProtection(SC): Organizationsmust:(i)monitor,control,andprotect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems; and (ii) employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.
SystemandInformationIntegrity(SI): Organizationsmust:(i)identify,report,andcorrectinformationand information system flaws in a timely manner; (ii) provide protection from malicious code at appropriate locations within organizational information systems; and (iii) monitor information system security alerts and advisories and take appropriate actions in response.
Minimum Security Requirements for Federal Information and Information Systems
http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf
FIPS PUB 200
FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION
3 MINIMUM SECURITY REQUIREMENTS
The minimum security requirements cover seventeen security-related areas with regard to protecting the confidentiality, integrity, and availability of federal information systems and the information processed, stored, and transmitted by those systems. The security-related areas include: (i) access control; (ii) awareness and training; (iii) audit and accountability; (iv) certification, accreditation, and security assessments; (v) configuration management; (vi) contingency planning; (vii) identification and authentication; (viii) incident response; (ix) maintenance; (x) media protection; (xi) physical and environmental protection; (xii) planning; (xiii) personnel security; (xiv) risk assessment; (xv) systems and services acquisition; (xvi) system and communications protection; and (xvii) system and information integrity. The seventeen areas represent a broad-based, balanced information security program that addresses the management, operational, and technical aspects of protecting federal information and information systems.
Specifications for Minimum Security Requirements
AccessControl(AC): Organizationsmustlimitinformationsystemaccesstoauthorizedusers,processes acting on behalf of authorized users, or devices (including other information systems) and to the types of transactions and functions that authorized users are permitted to exercise.
AwarenessandTraining(AT): Organizationsmust:(i)ensurethatmanagersandusersoforganizational information systems are made aware of the security risks associated with their activities and of the applicable laws, Executive Orders, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems; and (ii) ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.
AuditandAccountability(AU): Organizationsmust:(i)create,protect,andretaininformationsystemaudit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity; and (ii) ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.
Certification,Accreditation,andSecurityAssessments(CA): Organizationsmust:(i)periodicallyassessthe security controls in organizational information systems to determine if the controls are effective in their application; (ii) develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems; (iii) authorize the operation of organizational information systems and any associated information system connections; and (iv) monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.
2
FIPS Publication 200 Minimum Security Requirements for Federal Information and Information Systems
________________________________________________________________________________________________
ConfigurationManagement(CM): Organizationsmust:(i)establishandmaintainbaselineconfigurationsand inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; and (ii) establish and enforce security configuration settings for information technology products employed in organizational information systems.
ContingencyPlanning(CP): Organizationsmustestablish,maintain,andeffectivelyimplementplansfor emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations.
IdentificationandAuthentication(IA): Organizationsmustidentifyinformationsystemusers,processes acting on behalf of users, or devices and authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
IncidentResponse(IR): Organizationsmust:(i)establishanoperationalincidenthandlingcapabilityfor organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities; and (ii) track, document, and report incidents to appropriate organizational officials and/or authorities.
Maintenance(MA): Organizationsmust:(i)performperiodicandtimelymaintenanceonorganizational information systems; and (ii) provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.
MediaProtection(MP): Organizationsmust:(i)protectinformationsystemmedia,bothpaperanddigital;(ii) limit access to information on information system media to authorized users; and (iii) sanitize or destroy information system media before disposal or release for reuse.
Physical and Environmental Protection (PE): Organizations must: (i) limit physical access to information systems, equipment, and the respective operating environments to authorized individuals; (ii) protect the physical plant and support infrastructure for information systems; (iii) provide supporting utilities for information systems; (iv) protect information systems against environmental hazards; and (v) provide appropriate environmental controls in facilities containing information systems.
Planning(PL): Organizationsmustdevelop,document,periodicallyupdate,andimplementsecurityplans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing the information systems.
PersonnelSecurity(PS): Organizationsmust:(i)ensurethatindividualsoccupyingpositionsof responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions; (ii) ensure that organizational information and information systems are protected during and after personnel actions such as terminations and transfers; and (iii) employ formal sanctions for personnel failing to comply with organizational security policies and procedures.
Risk Assessment (RA): Organizations must periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information.
SystemandServicesAcquisition(SA): Organizationsmust:(i)allocatesufficientresourcestoadequately protect organizational information systems; (ii) employ system development life cycle processes that incorporate information security considerations; (iii) employ software usage and installation restrictions; and (iv) ensure that third-party providers employ adequate security measures to protect information, applications, and/or services outsourced from the organization.
3
FIPS Publication 200 Minimum Security Requirements for Federal Information and Information Systems
________________________________________________________________________________________________
SystemandCommunicationsProtection(SC): Organizationsmust:(i)monitor,control,andprotect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems; and (ii) employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.
SystemandInformationIntegrity(SI): Organizationsmust:(i)identify,report,andcorrectinformationand information system flaws in a timely manner; (ii) provide protection from malicious code at appropriate locations within organizational information systems; and (iii) monitor information system security alerts and advisories and take appropriate actions in response.
Computer security
Computer Security Resources Centre in USA
http://csrc.nist.gov/index.html
Computer Security Division, National Institute of Standards and Technology (NIST)
http://csrc.nist.gov/index.html
Computer Security Division, National Institute of Standards and Technology (NIST)
Subscribe to:
Posts (Atom)