ISSAF-PEOPLE,PROCESS & TECHNOLOGY
From OISSG
| 1. EXECUTIVE SUMMARY |
| 2. ABOUT ISSAF |
| 3. THE FRAMEWORK |
| 4. ENGAGEMENT MANAGEMENT |
| 5. GOOD PRACTICES– PRE ASSESSMENT, ASSESSMENT AND POST ASSESSMENT |
| 6. RISK ASSESSMENT |
| 7. ENTERPRISE INFORMATION SECURITY POLICY |
| 8. ENTERPRISE INFORMAITON SECURITY ORGANIZATION & MANAGEMENT |
| 9. ENTERPRISE SECURITY & CONTROLS ASSESSMENT |
| -- PERSONNEL SECURITY -- |
| -- TECHNICAL CONTROLS AND SECURITY ASSESSMENT -- |
| A. UNDERSTANDING ASSESSMENT TRENDS |
| B. PENETRATION TESTING METHODOLOGY |
| 10. PHYSICAL SECURITY ASSESSMENT |
| 11. ENTERPRISE SECURITY OPERATIONS MANAGEMENT |
| 12. ENTERPRISE CHANGE MANAGEMENT |
| 13. ENTERPRISE SECURITY AWARENESS |
| 14. ENTERPRISE INCIDENT MANAGEMENT |
| 15. OUTSOURCING SECURITY CONCERNS |
| 16. BUSINESS CONTINUITY MANAGEMENT |
| 17. LEGAL AND REGULATORY COMPLIANCE |
| -- ANNEXURE - KNOWLEDGE BASE -- |
| 1. TEMPLATES AND OTHERS |
| 2. BUILD FOUNDATION |
| 3. WINDOWS (DESKTOP) SECURITY CHECKLIST |
| 4. LINUX SECURITY CHECKLIST |
| 5. SOLARIS SECURITY CHECKLIST |
| 6. LINKS |
| 7. TEAM |
| 8. FEEDBACK FORM |
