Cyber Security Standards

Karen A. Scarfone, Daniel R Benigni, Tim Grance · Wiley Handbook of Science and Technology for Homeland Security · 2008

Abstract The goal of cyber security standards is to improve the security of information technology (IT) systems, networks, and critical infrastructures. A cyber security standard defines both functional and assurance requirements within a product, system, process, or technology environment. Well‐developed cyber security standards enable consistency among product developers and serve as a reliable metric for purchasing security products. Cyber security standards cover a broad range of granularity, from the mathematical definition of a cryptographic algorithm to the specification of security features in a web browser, and are typically implementation independent. A standard must address user needs, but must also be practical since cost and technological limitations must be considered in building products to meet the standard. Additionally, a standard's requirements must be verifiable; otherwise, users cannot assess security even when products are tested against the standard.

Read the paper · More papers on PaperTik