Standards, Guides and Regulatory Aspects
Jean‐Marie Flaus · 2019
The ISO 27000 family of standards defines good practices for information system security management. These have evolved over the years and are part of the general ISO 31000 framework, which describes the principles and guidelines for risk management, as well as the implementation processes at strategic and operational level. The SAE J306 standard, which concerns motor vehicles, was developed with the ISO 26262 operational safety standard in mind. It describes a structured process to reduce the probability of a successful attack. It provides detailed and structured coverage of security issues. BS7799 (2002) is a British standard describing good practices for information security management, consisting of three parts. It provides detailed and structured coverage of security issues. It has been incorporated into standards 27001:2013 and 27002:2013. Standard 61508 (and its derivatives) describes the functional safety approach to ensure that a system presents a risk below a set threshold for the various hazards it may encounter.