ISO/IEC JTC1/SC7 /N3040

Size: px
Start display at page:

Download "ISO/IEC JTC1/SC7 /N3040"

Transcription

1 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N Document Type Title Source Report ISO/IEC JTC 1/SC7 WG9 Report to the Brisbane Plenary AG Meeting WG9 Covener Project Status Final Reference Action ID FYI or ACT Due Date Distribution AG No. of Pages 16 Note Address reply to: ISO/IEC JTC1/SC7 Secretariat École de technologie supérieure Département de génie électrique 1100 Notre Dame Ouest, Montréal, Québec Canada H3C 1K3

2 Paul R. Croll Chair, IEEE Software and Systems Engineering Standards Committee Convener, ISO/IEC JTC1/SC7 WG9 An Overview of Standards Supporting System and Software Assurance and the SC7/WG9 Program of Work

3 How Does Assurance Fit in the System and Software Life Cycles?

4 Life Cycle Process Framework Standards System Life Cycle ISO/IEC 15288, Systems engineering System life cycle processes Software Life Cycle ISO/IEC 12207, Standard for Information Technology Software life cycle processes SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 3

5 Assurance in the ISO/IEC System Life Cycle Process Framework SYSTEM LIFE CYCLE (25) Safety, Security, Integrity ENTERPRISE(5) AGREEMENT (2) PROJECT (7) SYSTEM LIFE CYCLE MANAGEMENT RESOURCE MANAGEMENT QUALITY MANAGEMENT PROJECT PLANNING TECHNICAL (11) ACQUISITION SUPPLY ENTERPRISE ENVIRONMENT MANAGEMENT INVESTMENT MANAGEMENT PROJECT ASSESSMENT PROJECT CONTROL DECISION MAKING RISK MANAGEMENT CONFIGURATION MANAGEMENT INFORMATION MANAGEMENT STAKEHOLDER REQUIREMENTS DEFINITION REQUIREMENTS ANALYSIS ARCHITECTURAL DESIGN IMPLEMENTATION INTEGRATION VERIFICATION TRANSITION VALIDATION OPERATION MAINTENANCE DISPOSAL SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 4

6 Assurance in the IEEE/EIA Software Life Cycle Process Framework SOFTWARE LIFE CYCLE (17+1) Safety, Security, Integrity SUPPORTING (8) PRIMARY (5) DOCUMENTATION CONFIGURATION MANAGEMENT QUALITY ASSURANCE VERIFICATION VALIDATION ACQUISITION SUPPLY DEVELOPMENT OPERATION MAINTENANCE JOINT REVIEW AUDIT PROBLEM RESOLUTION ISO/IEC Risk Management Adapted from: Raghu Singh, An Introduction to International Standards ISO/IEC 12207, Software Life Cycle Processes, ORGANIZATIONAL (4) MANAGEMENT INFRASTRUCTURE IMPROVEMENT TRAINING TAILORING SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 5

7 What Standards Organizations Support System and Software Assurance?

8 Standards Organizations Supporting System and Software Assurance ISO IEC TC176 JTC1 TC56 SC65A Quality Information Technology Dependability Functional Safety SC1 SC7 SC22 SC27 Terminology Software Engineering Language, OS IT Security Techniques ISO IEEE CS IEC FISMA Projects IEEE CS S2ESC Software and Systems Engineering IASC Information Assurance SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 7

9 Dependability Standards IEC Dependability vocabulary IEC Programme management IEC Programme elements & tasks ISO IEC IEC SW aspects of dependability Risk Analysis IEC Risk analysis of technological sys Risk Control ISO/IEC Integrity levels Achieving Confidence ISO/IEC NWI Tech. & tools for confidence IEC 1025 Fault tree analysis IEC 812 Failure mode and effects analysis ISO/IEC System life cycle processes ISO/IEC SW life cycle processes Risk Management Adapted from James W. Moore, Software Engineering Standards: A User's Road Map, IEEE Computer Society Press, Los Alamitos, CA, 1997 ISO/IEC Risk Management SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 8

10 Safety and Security Standards IEC Functional Safety IEEE/EIA SW life cycle processes IEEE 1228 SW safety plans Safety IEC Sector-Specific Standards IEC SW in nuclear power safety systems IEC Programmable electrical medical systems DO 178B SW considerations in airborne equip certification IEEE CS RTCA ISO/IEC Common Criteria for IT Security Evaluation ISO/IEC Security frameworks for open systems ISO/IEC 9796 Digital Security Schemes ISO/IEC Systems Security Engineering CMM Security ISO IEEE/EIA SW life cycle processes IEEE P1619 Standard Architecture for Encrypted Shared Storage Media IEEE P1700 Security Architecture for Certification and Accreditation of Information IEEE P2200 Baseline Operating System Security IEEE CS SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 9

11 SC7 WG9 Overview

12 WG9 Terms of Reference Development of standards and technical reports for system and software assurance. System and software assurance addresses management of risk and assurance of safety, security, and dependability within the context of system and software life cycles. SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 11

13 Current NB Membership Australia Japan United Kingdom (Secretariat) United States (Convener) SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 12

14 SC7 WG9 Current Projects

15 SC7/WG9 Current Projects Revision of ISO/IEC Revision of ISO/IEC SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 14

16 SC7 WG9 Business Objectives

17 Near Term Objectives Complete the revision of ISO/IEC Complete the revision of ISO/IEC Determine the viability of the NWI for and either provide and editor or cancel the NWI. Establish liaisons with IEC TC56, TC65A, JTC1/SC27 and any other standards bodies whose program of work relates to system and software assurance, for the purposes of harmonization and collaboration on a unified body of work to meet users needs. Establish a Study Group to determine the derived system and software assurance requirements from ISO/IEC 15288, ISO/IEC 12207, and ISO/IEC 15026, and to recommend requirements for the development, modification, adoption, or reference of supporting standards. Expand the membership of WG9 to include participation from additional national bodies. SSTC 2004, Monday 19 April 2004, Track 1, 1440 Paul R. Croll Slide 16

ISO/IEC JTC1/SC7 /N3945

ISO/IEC JTC1/SC7 /N3945 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3945 2008-03-16 Document Type Calling Notice and Draft Agenda Calling Notice and Draft Agenda - JTC1/SC7 WG7

More information

ISO/IEC JTC1/SC7 /N3016

ISO/IEC JTC1/SC7 /N3016 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3016 2004-04-07 Document Type Title Source Framework Framework for ISO/IEC System and Software Engineering

More information

ISO/IEC JTC1/SC7 /N4314

ISO/IEC JTC1/SC7 /N4314 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N4314 Document Type Liaison Presentation 2009-06-15 Title Source Presentation IEEE-CS Liaison Report to the

More information

ISO/IEC JTC1/SC7 /N3287

ISO/IEC JTC1/SC7 /N3287 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3287 2005-06-20 Document Type Title Source Meeting Minutes, Meeting Minutes, WG7, Life Cycle Management, Helsinki,

More information

ISO/IEC JTC1/SC7 /N3037

ISO/IEC JTC1/SC7 /N3037 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3037 2004-05-10 Document Type Title Source Report ISO/IEC JTC 1/ to the Brisbane Plenary SC7 Secretariat Project

More information

ISO/IEC JTC1/SC7 /N3647

ISO/IEC JTC1/SC7 /N3647 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3647 2006-12-11 Document Type Title Source Meeting Minute Meeting Minutes, WG42, Architecture, Seoul, Republic

More information

ISO/IEC JTC1/SC7 3810

ISO/IEC JTC1/SC7 3810 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 3810 2007-07-23 Document Type Title Source NWIP NWI Proposal - Information Technology Service Management - -

More information

ISO/IEC JTC1/SC7 /N2667

ISO/IEC JTC1/SC7 /N2667 ISO/IEC JTC1/SC7 Stware and System Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N2667 2002-07-05 Document Type Title Meeting Minutes WG19, ODP - Modelling Languages, Meeting Minutes, Busan,

More information

International Software & Systems Engineering Standards

International Software & Systems Engineering Standards This presentation represents the opinion of the author and does not present positions of The MITRE Corporation or of the U.S. Department of Defense. Jim Moore The MITRE Corporation Chair, US TAG to ISO/IEC

More information

ISO/IEC JTC1/SC7 /N3614

ISO/IEC JTC1/SC7 /N3614 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3614 2006-10-15 Document Type Title Source NP Possible Proposal Possible proposal for testing standards BSI

More information

ISO/IEC JTC1/SC7 /N3848

ISO/IEC JTC1/SC7 /N3848 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3848 2007-09-10 Document Type Title Source Report Frameworks in ISO/IEC 42010 (DIS 25961) WG42 Project 42010

More information

ISO/IEC JTC1/SC7 /N2736

ISO/IEC JTC1/SC7 /N2736 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N2736 2002-11-18 Document Type Title Source Comment Disposition Report Comment Disposition Report, on N2733

More information

ISO/IEC JTC1/SC7 /N3209

ISO/IEC JTC1/SC7 /N3209 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3209 2005-05-17 Document Type Title Liaison Documents Liaison statements from ITU-T SG 17 Source ITU-T SG

More information

ISO/IEC JTC1/SC7 N3640

ISO/IEC JTC1/SC7 N3640 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 N3640 2006-12-08 Document Type: WG25 Meeting Minutes Title: Meeting Minutes, WG25, Service Management, Seoul,

More information

Summary of Contents LIST OF FIGURES LIST OF TABLES

Summary of Contents LIST OF FIGURES LIST OF TABLES Summary of Contents LIST OF FIGURES LIST OF TABLES PREFACE xvii xix xxi PART 1 BACKGROUND Chapter 1. Introduction 3 Chapter 2. Standards-Makers 21 Chapter 3. Principles of the S2ESC Collection 45 Chapter

More information

Seminar themes (1 of 3) IEEE/EIA 12207:1995 Software Life Cycle Processes. Seminar themes (3 of 3) Seminar themes (2 of 3)

Seminar themes (1 of 3) IEEE/EIA 12207:1995 Software Life Cycle Processes. Seminar themes (3 of 3) Seminar themes (2 of 3) IEEE/EIA 12207 - Software Life Cycle 12207 - Unit 1 - JWM - 9801 12207 - Unit 1 - JWM - 9801 Unit 1 1 12207 - Unit 1 - JWM - 9801 2 Seminar themes (1 of 3) IEEE/EIA 12207:1995 Software Life Cycle Prepared

More information

Engineering for System Assurance Legacy, Life Cycle, Leadership

Engineering for System Assurance Legacy, Life Cycle, Leadership Engineering for System Assurance Legacy, Life Cycle, Leadership Paul R. Croll Computer Sciences Corporation pcroll@csc.com Industry Co-Chair, NDIA Systems Assurance Committee Chair, DHS Software Assurance

More information

Security Standardization

Security Standardization ISO-ITU ITU Cooperation on Security Standardization Dr. Walter Fumy Chairman ISO/IEC JTC 1/SC 27 Chief Scientist, Bundesdruckerei GmbH, Germany 7th ETSI Security Workshop - Sophia Antipolis, January 2012

More information

ISO/IEC JTC1/SC7 /N3652

ISO/IEC JTC1/SC7 /N3652 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N3652 2006-12-17 Document Type Title Source Meeting Minutes Meeting Minutes, JTC1/SC7/WG6: Evaluation and Metrics,

More information

ISO/IEC JTC 1 N Replaces: ISO/IEC JTC 1 Information Technology

ISO/IEC JTC 1 N Replaces: ISO/IEC JTC 1 Information Technology ISO/IEC JTC 1 N7401 2004-03-17 Replaces: ISO/IEC JTC 1 Information Technology Document Type: Document Title: Meeting Report Meeting Minutes and Resolutions of the Web Services Study Group, 26-27 February

More information

ISO/IEC JTC 1 N 13145

ISO/IEC JTC 1 N 13145 ISO/IEC JTC 1 N 13145 ISO/IEC JTC 1 Information technology Secretariat: ANSI (United States) Document type: Title: Status: Business Plan BUSINESS PLAN FOR ISO/IEC JTC 1/SC 40, IT SERVICE MANAGEMENT AND

More information

INTERNATIONAL STANDARD

INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 90003 First edition 2004-02-15 Software engineering Guidelines for the application of ISO 9001:2000 to computer software Ingénierie du logiciel Lignes directrices pour l'application

More information

ISO/IEC/ IEEE Systems and software engineering Content of life-cycle information items (documentation)

ISO/IEC/ IEEE Systems and software engineering Content of life-cycle information items (documentation) This is a preview - click here to buy the full publication INTERNATIONAL STANDARD ISO/IEC/ IEEE 15289 Second edition 2015-05-15 Systems and software engineering Content of life-cycle information items

More information

ISO/IEC JTC 1/SC 27 N7769

ISO/IEC JTC 1/SC 27 N7769 ISO/IEC JTC 1/SC 27 N7769 REPLACES: N ISO/IEC JTC 1/SC 27 Information technology - Security techniques Secretariat: DIN, Germany DOC TYPE: officer's contribution TITLE: SC 27 Presentation to ITU-T Workshop

More information

ISO/IEC ISO/IEC

ISO/IEC ISO/IEC ISO/IEC 27000 2010 6 3 1. ISO/IEC 27000 ISO/IEC 27000 ISMS ISO IEC ISO/IEC JTC1 SC 27 ISO/IEC 27001 ISO/IEC 27000 ISO/IEC 27001 ISMS requirements ISO/IEC 27000 ISMS overview and vocabulary ISO/IEC 27002

More information

ISO/IEC JTC1/SC7 N4379

ISO/IEC JTC1/SC7 N4379 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 N4379 2009-07-16 Document Type Title Source NWIP NWIP, Software Engineering - Software product Quality Requirements

More information

ISO/IEC INTERNATIONAL STANDARD. Systems and software engineering Measurement process. Ingénierie des systèmes et du logiciel Processus de mesure

ISO/IEC INTERNATIONAL STANDARD. Systems and software engineering Measurement process. Ingénierie des systèmes et du logiciel Processus de mesure INTERNATIONAL STANDARD ISO/IEC 15939 Second edition 2007-08-01 Corrected version 2008-10-01 Systems and software engineering Measurement process Ingénierie des systèmes et du logiciel Processus de mesure

More information

ISO/IEC JTC1/SC7 /N2975

ISO/IEC JTC1/SC7 /N2975 ISO/IEC JTC1/SC7 Software and Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 /N2975 2004-01-19 Document Type Title Source Comment Disposition Report Comment Disposition Report - CD 25020

More information

ISO/IEC JTC 1 N 13538

ISO/IEC JTC 1 N 13538 ISO/IEC JTC 1 N 13538 ISO/IEC JTC 1 Information technology Secretariat: ANSI (United States) Document type: Business Plan Title: SC 41 Business Plan and Dashboard 2017 Status: This document is circulated

More information

Frequently Asked Questions

Frequently Asked Questions December 2001 Introduction International Standard ISO/IEC 17799:2000 Information Security Management, Code of Practice for Information Security Management Frequently Asked Questions The National Institute

More information

Engineering Practices for System Assurance

Engineering Practices for System Assurance Engineering Practices for System Assurance NDIA System Assurance Committee Presented by Paul R. Croll Industry Co-Chair Computer Sciences Corporation pcroll@csc.com 1 Outline Definition Of The Problem

More information

Reported by Jim Moore, The MITRE Corporation, ,

Reported by Jim Moore, The MITRE Corporation, , ISO/IEC JTC 1/SC 22/WG 9 N 454 Meeting Report: ISO/IEC JTC 1/SC 22 (Programming Languages, Operating Systems and Environments), 29 September to 2 October 2005, Mont Tremblant, Quebec, Canada Reported by

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management INTERNATIONAL STANDARD ISO/IEC 27005 Second edition 2011-06-01 Information technology Security techniques Information security risk management Technologies de l'information Techniques de sécurité Gestion

More information

Report on ISO/IEC/JTC1/SC27 Activities in Digital Identities

Report on ISO/IEC/JTC1/SC27 Activities in Digital Identities International Telecommunication Union ITU-T Report on ISO/IEC/JTC1/SC27 Activities in Digital Identities Dick Brackney ISO/SC27 Liaison Officer to ITU-T SG17 Standards Program Manager, U.S. Dept of Defense

More information

ISO/IEC JTC 1 Study Group on Smart Cities

ISO/IEC JTC 1 Study Group on Smart Cities ANSI WORKSHOP ISO/IEC JTC 1 Study Group on Smart Cities Presented by Alex Tarpinian Senior Manager, IBM ANSI WORKSHOP: Smart and Sustainable Cities November 21, 2013 1 Overview ISO/IEC JTC 1 Study Group

More information

Information technology Process assessment Concepts and terminology

Information technology Process assessment Concepts and terminology Provläsningsexemplar / Preview INTERNATIONAL STANDARD ISO/IEC 33001 Second edition 2015-03-01 Information technology Process assessment Concepts and terminology Technologies de l information Évaluation

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 15426-1 Second edition 2006-06-01 Information technology Automatic identification and data capture techniques Bar code verifier conformance specification Part 1: Linear symbols

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management system implementation guidance

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management system implementation guidance INTERNATIONAL STANDARD ISO/IEC 27003 First edition 2010-02-01 Information technology Security techniques Information security management system implementation guidance Technologies de l'information Techniques

More information

ISO/IEC TR TECHNICAL REPORT. Information technology Security techniques A framework for IT security assurance Part 2: Assurance methods

ISO/IEC TR TECHNICAL REPORT. Information technology Security techniques A framework for IT security assurance Part 2: Assurance methods TECHNICAL REPORT ISO/IEC TR 15443-2 First edition 2005-09-01 Information technology Security techniques A framework for IT security assurance Part 2: Assurance methods Technologies de l'information Techniques

More information

ISO/IEC JTC1/SC7 N2830,

ISO/IEC JTC1/SC7 N2830, ISO/IEC JTC1/SC7 Software & Systems Engineering Secretariat: CANADA (SCC) ISO/IEC JTC1/SC7 N2830, 2003-05-09 Document Type Letter Ballot Summary Title Letter Ballot Summary CD 25020: Software and Systems

More information

ISO/IEC JTC 1 Update. April 2018 Phil Wennblom, Chair

ISO/IEC JTC 1 Update. April 2018 Phil Wennblom, Chair ISO/IEC JTC 1 Update April 2018 Phil Wennblom, Chair 1 About JTC 1 Joint TC of ISO and IEC in the field of Information Technology 33 P-members and 62 O-members Organized in 22 SCs and 2 JTC 1 WGs About

More information

Information technology Process assessment Process measurement framework for assessment of process capability

Information technology Process assessment Process measurement framework for assessment of process capability INTERNATIONAL STANDARD ISO/IEC 33020 Second edition 2015-03-01 Information technology Process assessment Process measurement framework for assessment of process capability Technologies de l information

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management systems Overview and vocabulary

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management systems Overview and vocabulary INTERNATIONAL STANDARD ISO/IEC 27000 Second edition 2012-12-01 Information technology Security techniques Information security management systems Overview and vocabulary Technologies de l'information Techniques

More information

Agenda. New ISO/IEC developments in Process Assessment standards for IT Services. Antonio Coletta DNV IT Global Services

Agenda. New ISO/IEC developments in Process Assessment standards for IT Services. Antonio Coletta DNV IT Global Services New ISO/IEC developments in Assessment standards for IT Services Antonio Coletta DNV IT Global Services Head of Italian delegation to ISO/IEC JTC1 SC7 email:tony.coletta@virgilio.it SPICE Days 2008 23-25

More information

ISO/IEC TR TECHNICAL REPORT. Systems and software engineering Life cycle management Part 1: Guide for life cycle management

ISO/IEC TR TECHNICAL REPORT. Systems and software engineering Life cycle management Part 1: Guide for life cycle management TECHNICAL REPORT ISO/IEC TR 24748-1 First edition 2010-10-01 Systems and software engineering Life cycle management Part 1: Guide for life cycle management Ingénierie des systèmes et du logiciel Gestion

More information

ISO/IEC JTC 1 N Replaces: ISO/IEC JTC 1 Information Technology

ISO/IEC JTC 1 N Replaces: ISO/IEC JTC 1 Information Technology ISO/IEC JTC 1 N7528 2004-08-27 Replaces: ISO/IEC JTC 1 Information Technology Document Type: Document Title: Meeting Report Minutes and Resolutions from the Web Services Study Group Meeting, June 2004

More information

Information technology Service management. Part 10: Concepts and vocabulary

Information technology Service management. Part 10: Concepts and vocabulary Provläsningsexemplar / Preview INTERNATIONAL STANDARD ISO/IEC 20000-10 First edition 2018-09 Information technology Service management Part 10: Concepts and vocabulary Technologies de l'information Gestion

More information

ISO/IEC TR TECHNICAL REPORT. Information technology Security techniques Information security management guidelines for financial services

ISO/IEC TR TECHNICAL REPORT. Information technology Security techniques Information security management guidelines for financial services TECHNICAL REPORT ISO/IEC TR 27015 First edition 2012-12-01 Information technology Security techniques Information security management guidelines for financial services Technologies de l'information Techniques

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management INTERNATIONAL STANDARD ISO/IEC 27005 First edition 2008-06-15 Information technology Security techniques Information security risk management Technologies de l'information Techniques de sécurité Gestion

More information

ISO/IEC INTERNATIONAL STANDARD. Identification cards Machine readable travel documents Part 3: Machine readable official travel documents

ISO/IEC INTERNATIONAL STANDARD. Identification cards Machine readable travel documents Part 3: Machine readable official travel documents INTERNATIONAL STANDARD ISO/IEC 7501-3 Second edition 2005-10-15 Identification cards Machine readable travel documents Part 3: Machine readable official travel documents Cartes d'identification Documents

More information

Information technology Service management. Part 10: Concepts and terminology

Information technology Service management. Part 10: Concepts and terminology TECHNICAL REPORT ISO/IEC TR 20000-10 Second edition 2015-11-01 Information technology Service management Part 10: Concepts and terminology Technologies de l information Gestion des services Partie 10:

More information

INTERNATIONAL STANDARD

INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 25000 Second edition 2014-03-15 Systems and software engineering Systems and software Quality Requirements and Evaluation (SQuaRE) Guide to SQuaRE Ingénierie des systèmes

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 27006 Second edition 2011-12-01 Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems

More information

International Standard ISO/IEC 17799:2000 Code of Practice for Information Security Management. Frequently Asked Questions

International Standard ISO/IEC 17799:2000 Code of Practice for Information Security Management. Frequently Asked Questions November 2002 International Standard ISO/IEC 17799:2000 Code of Practice for Information Security Management Introduction Frequently Asked Questions The National Institute of Standards and Technology s

More information

IEEE RS Standards Status and Descriptions, and Collaboration Efforts. Lou Gullo June 9, 2010

IEEE RS Standards Status and Descriptions, and Collaboration Efforts. Lou Gullo June 9, 2010 IEEE RS Standards Status and Descriptions, and Collaboration Efforts Lou Gullo June 9, 2010 Summary IEEE Reliability Standards Status Collaboration with IEEE Computer Society Standards Collaboration with

More information

Introduction to Conformity Assessment and ISO/CASCO Tool Box

Introduction to Conformity Assessment and ISO/CASCO Tool Box www.aeconformity.com Introduction to Conformity Assessment and ISO/CASCO Tool Box Alex Ezrakhovich Co-convener of APG & AAPG Sydney, Australia 5th International Conference on Quality Management October

More information

Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems

Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems Provläsningsexemplar / Preview INTERNATIONAL STANDARD ISO/IEC 27006 Third edition 2015-10-01 Information technology Security techniques Requirements for bodies providing audit and certification of information

More information

Synergies of the Common Criteria with Other Standards

Synergies of the Common Criteria with Other Standards Synergies of the Common Criteria with Other Standards Mark Gauvreau EWA-Canada 26 September 2007 Presenter: Mark Gauvreau (mgauvreau@ewa-canada.com) Overview Purpose Acknowledgements Security Standards

More information

ISO/IEC TR TECHNICAL REPORT

ISO/IEC TR TECHNICAL REPORT TECHNICAL REPORT ISO/IEC TR 15443-3 First edition 2007-12-15 Information technology Security techniques A framework for IT security assurance Part 3: Analysis of assurance methods Technologies de l'information

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 15408-1 Third edition 2009-12-15 Information technology Security techniques Evaluation criteria for IT security Part 1: Introduction and general model Technologies de l'information

More information

Integration Technologies Group, Inc. Uncompromising Performance

Integration Technologies Group, Inc. Uncompromising Performance Integration Technologies Group, Inc. Uncompromising Performance Agenda Current Market Information Overview of ISO 27001 Overview of ISO 27001 Requirements, Controls and Assets Identify the Scope Overview

More information

ISO/IEC JTC 1 N 11326

ISO/IEC JTC 1 N 11326 ISO/IEC JTC 1 N 11326 ISO/IEC JTC 1 Information technology Secretariat: ANSI (USA) Document type: Title: Status: Officer's Contribution SC 7 Chairman's Presentation to the November meeting in Jeju This

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 13335-1 First edition 2004-11-15 Information technology Security techniques Management of information and communications technology security Part 1: Concepts and models for

More information

Information technology Guidelines for the application of ISO 9001:2008 to IT service management and its integration with ISO/IEC :2011

Information technology Guidelines for the application of ISO 9001:2008 to IT service management and its integration with ISO/IEC :2011 TECHNICAL REPORT ISO/IEC TR 90006 First edition 2013-11-01 Information technology Guidelines for the application of ISO 9001:2008 to IT service management and its integration with ISO/IEC 20000-1:2011

More information

The Analysis and Proposed Modifications to ISO/IEC Software Engineering Software Quality Requirements and Evaluation Quality Requirements

The Analysis and Proposed Modifications to ISO/IEC Software Engineering Software Quality Requirements and Evaluation Quality Requirements Journal of Software Engineering and Applications, 2016, 9, 112-127 Published Online April 2016 in SciRes. http://www.scirp.org/journal/jsea http://dx.doi.org/10.4236/jsea.2016.94010 The Analysis and Proposed

More information

ISO/IEC INTERNATIONAL STANDARD. Conformity assessment Requirements for bodies certifying products, processes and services

ISO/IEC INTERNATIONAL STANDARD. Conformity assessment Requirements for bodies certifying products, processes and services INTERNATIONAL STANDARD ISO/IEC 17065 First edition 2012-09-15 Conformity assessment Requirements for bodies certifying products, processes and services Évaluation de la conformité Exigences pour les organismes

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Cloud computing Overview and vocabulary

ISO/IEC INTERNATIONAL STANDARD. Information technology Cloud computing Overview and vocabulary INTERNATIONAL STANDARD ISO/IEC 17788 First edition 2014-10-15 Information technology Cloud computing Overview and vocabulary Technologies de l'information Informatique en nuage Vue d'ensemble et vocabulaire

More information

CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act''

CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act'' CEN Identification number in the EC register: 63623305522-13 CENELEC Identification number in the EC register: 58258552517-56 CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act''

More information

Software engineering Guidelines for the application of ISO 9001:2008 to computer software

Software engineering Guidelines for the application of ISO 9001:2008 to computer software INTERNATIONAL STANDARD ISO/IEC 90003 Second edition 2014-12-15 Software engineering Guidelines for the application of ISO 9001:2008 to computer software Ingénierie du logiciel Lignes directrices pour l

More information

ISO/IEC TR TECHNICAL REPORT. Software engineering Product quality Part 4: Quality in use metrics

ISO/IEC TR TECHNICAL REPORT. Software engineering Product quality Part 4: Quality in use metrics TECHNICAL REPORT ISO/IEC TR 9126-4 First edition 2004-04-01 Software engineering Product quality Part 4: Quality in use metrics Génie du logiciel Qualité des produits Partie 4: Qualité en métrologie d'usage

More information

ISO/IEC INTERNATIONAL STANDARD. Software engineering Software measurement process. Ingénierie du logiciel Méthode de mesure des logiciels

ISO/IEC INTERNATIONAL STANDARD. Software engineering Software measurement process. Ingénierie du logiciel Méthode de mesure des logiciels INTERNATIONAL STANDARD ISO/IEC 15939 First edition 2002-07-15 Software engineering Software measurement process Ingénierie du logiciel Méthode de mesure des logiciels Reference number ISO/IEC 15939:2002(E)

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Guideline for the evaluation and selection of CASE tools

ISO/IEC INTERNATIONAL STANDARD. Information technology Guideline for the evaluation and selection of CASE tools INTERNATIONAL STANDARD ISO/IEC 14102 Second edition 2008-11-01 Information technology Guideline for the evaluation and selection of CASE tools Technologies de l'information Lignes directrices pour l'évaluation

More information

An Information Model for Software Quality Measurement with ISO Standards

An Information Model for Software Quality Measurement with ISO Standards An Information Model for Software Measurement with ISO Standards Alain Abran École de Technologie Supérieure University of Québec, 1100 Notre -Dame Ouest, Montréal, Québec H3W 1T8, Canada aabran@ele.etsmtl.ca

More information

standards and so the text is not to be used for commercial purposes, gain or as a source of profit. Any changes to the slides or incorporation in

standards and so the text is not to be used for commercial purposes, gain or as a source of profit. Any changes to the slides or incorporation in ISO/IEC JTC 1/SC 27/WG 4 IT Security Controls and Services M. De Soete, ISO/IEC JTC 1 SC27 Vice Chair copyright ISO/IEC JTC 1/SC 27, 2014. This is an SC27 public document and is distributed as is for the

More information

B C ISO/IEC TR TECHNICAL REPORT

B C ISO/IEC TR TECHNICAL REPORT TECHNICAL REPORT ISO/IEC TR 13335-3 First edition 1998-06-15 Information technology Guidelines for the management of IT Security Part 3: Techniques for the management of IT Security Technologies de l'information

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Systems and software engineering FiSMA 1.1 functional size measurement method

ISO/IEC INTERNATIONAL STANDARD. Information technology Systems and software engineering FiSMA 1.1 functional size measurement method INTERNATIONAL STANDARD ISO/IEC 29881 Second edition 2010-08-15 Information technology Systems and software engineering FiSMA 1.1 functional size measurement method Technologies de l'information Ingénierie

More information

Sýnishorn ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management

Sýnishorn ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management INTERNATIONAL STANDARD ISO/IEC 27005 Second edition 2011-06-01 Information technology Security techniques Information security risk management Technologies de l'information Techniques de sécurité Gestion

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO/IEC/ IEEE 29119-3 First edition 2013-09-01 Software and systems engineering Software testing Part 3: Test documentation Ingénierie du logiciel et des systèmes Essais du logiciel

More information

ISO/IEC Information technology Security techniques Code of practice for information security controls

ISO/IEC Information technology Security techniques Code of practice for information security controls INTERNATIONAL STANDARD ISO/IEC 27002 Second edition 2013-10-01 Information technology Security techniques Code of practice for information security controls Technologies de l information Techniques de

More information

SC22/WG20 N677 Date: May 12, 1999

SC22/WG20 N677 Date: May 12, 1999 SC22/WG20 N677 Date: May 12, 1999 Business plan and convenor s report: ISO/IEC JTC1 SC22/WG20 - INTERNATIONALIZATION PERIOD COVERED: June 1998 - May 1999 SUBMITTED BY: Convenor WG20 Arnold F. Winkler Unisys

More information

ISO/IEC INTERNATIONAL STANDARD. Conformity assessment Supplier's declaration of conformity Part 1: General requirements

ISO/IEC INTERNATIONAL STANDARD. Conformity assessment Supplier's declaration of conformity Part 1: General requirements INTERNATIONAL STANDARD ISO/IEC 17050-1 First edition 2004-10-01 Conformity assessment Supplier's declaration of conformity Part 1: General requirements Évaluation de la conformité Déclaration de conformité

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO/IEC/ IEEE 16326 First edition 2009-12-15 Systems and software engineering Life cycle processes Project management Ingénierie du logiciel Processus de cycle de vie Gestion de

More information

INTERNATIONAL STANDARD

INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 27013 Second edition 2015-12-01 Information technology Security techniques Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 Technologies de

More information

ISO/IEC Status Report to T10

ISO/IEC Status Report to T10 30 October 2002 T10/02-453r0 ISO/IEC Status Report to T10 Gary S Robinson, IR 1. ISO/IEC JTC1/SC25 met. WG4 did not meet but did submit a status report and 9 resolutions to be approved by SC25. 2. List

More information

Information technology Security techniques Application security. Part 5: Protocols and application security controls data structure

Information technology Security techniques Application security. Part 5: Protocols and application security controls data structure This is a preview - click here to buy the full publication INTERNATIONAL STANDARD ISO/IEC 27034-5 First edition 2017-10 Information technology Security techniques Application security Part 5: Protocols

More information

INTERNATIONAL STANDARD

INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 27039 First edition 2015-02-15 Corrected version 2016-05-01 Information technology Security techniques Selection, deployment and operations of intrusion detection and prevention

More information

ISA99 - Industrial Automation and Controls Systems Security

ISA99 - Industrial Automation and Controls Systems Security ISA99 - Industrial Automation and Controls Systems Security Committee Summary and Activity Update Standards Certification Education & Training Publishing Conferences & Exhibits February 2018 Copyright

More information

GUIDE 63. Guide to the development and inclusion of safety aspects in International Standards for medical devices

GUIDE 63. Guide to the development and inclusion of safety aspects in International Standards for medical devices GUIDE 63 Guide to the development and inclusion of safety aspects in International Standards for medical devices Second edition 2012 ISO/IEC 2012 ISO/IEC GUIDE 63:2012(E) This is a preview - click here

More information

ISO/IEC INTERNATIONAL STANDARD. Software engineering Product evaluation Part 3: Process for developers

ISO/IEC INTERNATIONAL STANDARD. Software engineering Product evaluation Part 3: Process for developers INTERNATIONAL STANDARD ISO/IEC 14598-3 First edition 2000-02-01 Software engineering Product evaluation Part 3: Process for developers Ingénierie du logiciel Évaluation du produit Partie 3: Procédés pour

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 18000-1 Second edition 2008-07-01 Information technology Radio frequency identification for item management Part 1: Reference architecture and definition of parameters to

More information

SC22/WG20 N751 Date: June 29, 2000

SC22/WG20 N751 Date: June 29, 2000 SC22/WG20 N751 Date: June 29, 2000 Business plan and convenor s report: ISO/IEC JTC1 SC22/WG20 - INTERNATIONALIZATION PERIOD COVERED: September 1999 - September 2001 SUBMITTED BY: Convenor WG20 Arnold

More information

COPANT ANNUAL ASSEMBLY XXX PASC MEETING Together towards Standardization. Cartagena de Indias, Colombia April 22 to 27, 2007

COPANT ANNUAL ASSEMBLY XXX PASC MEETING Together towards Standardization. Cartagena de Indias, Colombia April 22 to 27, 2007 COPANT ANNUAL ASSEMBLY - 2007 XXX PASC MEETING 2007 Together towards Standardization Cartagena de Indias, Colombia April 22 to 27, 2007 REPORT OF PLENARIES OF CASCO AND IECEE BUENOS AIRES 2006 LIC. MARIO

More information

ISO/IEC JTC 1 N

ISO/IEC JTC 1 N ISO/IEC JTC 1 N 8667 2007-07-27 ISO/IEC JTC 1 Information Technology Replaces Document Type: Meeting Resolutions Document Title: Recommendations of the 24-26 July 2007 SWG-Directives Meeting, Paris, France

More information

ISO/IEC JTC 1 N 11737

ISO/IEC JTC 1 N 11737 ISO/IEC JTC 1 N 11737 ISO/IEC JTC 1 Information technology Secretariat: ANSI (United States) Document type: Business Plan Title: JTC 1 SC 39 Business Plan for the period November 2012 - November 2013 Status:

More information

ISA99 - Industrial Automation and Controls Systems Security

ISA99 - Industrial Automation and Controls Systems Security ISA99 - Industrial Automation and Controls Systems Security Committee Summary and Activity Update Standards Certification Education & Training Publishing Conferences & Exhibits September 2016 Copyright

More information

ISO/IEC TR TECHNICAL REPORT. Software Engineering Guide to the Software Engineering Body of Knowledge (SWEBOK) IEEE

ISO/IEC TR TECHNICAL REPORT. Software Engineering Guide to the Software Engineering Body of Knowledge (SWEBOK) IEEE TECHNICAL REPORT ISO/IEC TR 19759 IEEE First edition 2005-09-15 Software Engineering Guide to the Software Engineering Body of Knowledge (SWEBOK) Ingénierie du logiciel Guide du corps de connaissance de

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Code of practice for information security management

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Code of practice for information security management INTERNATIONAL STANDARD ISO/IEC 17799 Second edition 2005-06-15 Information technology Security techniques Code of practice for information security management Technologies de l'information Techniques de

More information

ISO INTERNATIONAL STANDARD. Condition monitoring and diagnostics of machines General guidelines on using performance parameters

ISO INTERNATIONAL STANDARD. Condition monitoring and diagnostics of machines General guidelines on using performance parameters INTERNATIONAL STANDARD ISO 13380 First edition 2002-04-01 Condition monitoring and diagnostics of machines General guidelines on using performance parameters Surveillance et diagnostic d'état des machines

More information

Information technology - Security techniques - Privacy framework

Information technology - Security techniques - Privacy framework INCITS/ISO/IEC 29100:2011[2012] (ISO/IEC 29100:2011, IDT) Information technology - Security techniques - Privacy framework INCITS/ISO/IEC 29100:2011[2012] PDF disclaimer This PDF file may contain embedded

More information

Information technology Security techniques Information security controls for the energy utility industry

Information technology Security techniques Information security controls for the energy utility industry INTERNATIONAL STANDARD ISO/IEC 27019 First edition 2017-10 Information technology Security techniques Information security controls for the energy utility industry Technologies de l'information Techniques

More information